CVE-2025-68643

A

xigen Mail Server before 10.5.57 allows stored Cross-Site Scripting (XSS) in the handling of the timeFormat account preference parameter. Attackers can exploit this by deploying a multi-stage attack. In the first stage, a malicious JavaScript payload is injected into the timeFormat preference by exploiting a separate vulnerability or using compromised credentials. In the second stage, when the victim logs into the WebMail interface, the unsanitized timeFormat value is loaded from storage and inserted into the DOM, causing the injected script to execute.

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:axigen:axigen_mail_server:*:*:*:*:*:*:*:*
cpe:2.3:a:axigen:axigen_mail_server:*:*:*:*:*:*:*:*

History

10 Feb 2026, 14:45

Type Values Removed Values Added
References () https://www.axigen.com/knowledgebase/Axigen-WebMail-Stored-XSS-Vulnerability-CVE-2025-68643-_405.html - () https://www.axigen.com/knowledgebase/Axigen-WebMail-Stored-XSS-Vulnerability-CVE-2025-68643-_405.html - Vendor Advisory
References () https://www.axigen.com/mail-server/download/ - () https://www.axigen.com/mail-server/download/ - Product
CPE cpe:2.3:a:axigen:axigen_mail_server:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : 6.1
v2 : unknown
v3 : 5.4
First Time Axigen
Axigen axigen Mail Server

09 Feb 2026, 18:16

Type Values Removed Values Added
CWE CWE-79
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1

05 Feb 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-05 17:16

Updated : 2026-02-11 21:16


NVD link : CVE-2025-68643

Mitre link : CVE-2025-68643

CVE.ORG link : CVE-2025-68643


JSON object : View

Products Affected
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')