
CVE-2025-68643 Axigen Mail Server before 10.5.57 allows stored Cross-Site Scripting (XSS) in the handling of the timeFormat account preference parameter. Attackers can exploit this … https://www.cve.org/CVERecord?id=CVE-2025-68643
Post summary
The CVE reveals a stored XSS flaw in Axigen Mail Server's timeFormat preference before version 10.5.57, with no mention of PoC, exploit code, or active exploitation.
