Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Atmail

First CVE: Feb 9, 2006Active for: 20 yearsTotal CVEs: 32
33.7
VTI Score
Medium

Atmail is a modestly represented webmail and messaging platform vendor whose vulnerability footprint centers on a focused suite of products including Atmail, Atmail Open, and Atmail WebMail, all serving as edge-facing communication systems. The vendor's disclosures recur through web-application input-handling weakness classes, notably cross-site scripting, path traversal, and cross-site request forgery, reflecting the risks inherent to browser-delivered email and administrative interfaces. Vulnerabilities affecting this vendor have frequently acquired public exploit tooling, consistent with the appeal of webmail systems to attackers seeking messaging access or account takeover. The exposure pattern is durable across the product line and suggests defenders should prioritize input-validation and session-security controls for deployed Atmail instances, particularly internet-facing administrative endpoints. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
32
Total CVEs
More Total CVEs than 97% of tracked vendors
0.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 4% of tracked vendors
6.6
Avg CVSS Score
Higher Avg CVSS Score than 43% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Atmail over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 9, 2006
20 years ago
Most Recent CVE
Feb 7, 2024
898 days ago

Products(6 total)

Top CVEs

Signals from CVEs in this vendor scope (32 CVEs).

32 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2012-2593MEDIUM
Cross-site scripting (XSS) vulnerability in the administrative interface in Atmail Webmail Server 6.4 allows remote attackers to inject arbitrary web script or HTML via the Date fi
Feb 6, 20206.134NOYES
CVE-2021-43574MEDIUM
WebAdmin Control Panel in Atmail 6.5.0 (a version released in 2012) allows XSS via the format parameter to the default URI. NOTE: This vulnerability only affects products that are
Nov 15, 20216.130NOYES
CVE-2013-5032HIGH
Unspecified vulnerability in Atmail before 6.6.4, and 7.x before 7.1.2, has unknown impact and attack vectors, a different vulnerability than CVE-2013-5031, CVE-2013-5033, and CVE-
Jan 12, 201410.030NONO
CVE-2017-9519HIGH
atmail before 7.8.0.2 has CSRF, allowing an attacker to create a user account.
Jun 8, 20178.827NONO
CVE-2017-9518HIGH
atmail before 7.8.0.2 has CSRF, allowing an attacker to change the SMTP hostname and hijack all emails.
Jun 8, 20178.827NONO
CVE-2017-9517HIGH
atmail before 7.8.0.2 has CSRF, allowing an attacker to upload and import users via CSV.
Jun 8, 20178.827NONO
CVE-2022-30776MEDIUM
atmail 6.5.0 allows XSS via the index.php/admin/index/ error parameter.
May 16, 20226.126NOYES
CVE-2024-24133CRITICAL
Atmail v6.6.0 was discovered to contain a SQL injection vulnerability via the username parameter on the login page.
Feb 7, 20249.825NONO
CVE-2013-5034HIGH
Unspecified vulnerability in Atmail before 6.6.4, and 7.x before 7.1.2, has unknown impact and attack vectors, a different vulnerability than CVE-2013-5031, CVE-2013-5032, and CVE-
Jan 12, 201410.025NONO
CVE-2013-5033HIGH
Unspecified vulnerability in Atmail before 6.6.4, and 7.x before 7.1.2, has unknown impact and attack vectors, a different vulnerability than CVE-2013-5031, CVE-2013-5032, and CVE-
Jan 12, 201410.025NONO
View all 32 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products32 CVEs
66%
31%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network9 (28.1%)
Unknown23 (71.9%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (28.1%)
High0 (0.0%)
Unknown23 (71.9%)
User Interaction
None1 (3.1%)
Unknown23 (71.9%)
Required8 (25.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None9 (28.1%)
Unknown23 (71.9%)

Exploit Exposure

Signals from CVEs in this vendor scope (32 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
6.2% of CVEs· 96th percentile
ExploitDB
5 CVEs
15.6% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Atmail.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Atmail — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Atmail's Products

View all 2 CNAs →

Top CWEs