Atmail is a modestly represented webmail and messaging platform vendor whose vulnerability footprint centers on a focused suite of products including Atmail, Atmail Open, and Atmail WebMail, all serving as edge-facing communication systems. The vendor's disclosures recur through web-application input-handling weakness classes, notably cross-site scripting, path traversal, and cross-site request forgery, reflecting the risks inherent to browser-delivered email and administrative interfaces. Vulnerabilities affecting this vendor have frequently acquired public exploit tooling, consistent with the appeal of webmail systems to attackers seeking messaging access or account takeover. The exposure pattern is durable across the product line and suggests defenders should prioritize input-validation and session-security controls for deployed Atmail instances, particularly internet-facing administrative endpoints. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Atmail over time
Signals from CVEs in this vendor scope (32 CVEs).
32 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-2593MEDIUM Cross-site scripting (XSS) vulnerability in the administrative interface in Atmail Webmail Server 6.4 allows remote attackers to inject arbitrary web script or HTML via the Date fi | Feb 6, 2020 | 6.1 | 34 | NO | YES |
CVE-2021-43574MEDIUM WebAdmin Control Panel in Atmail 6.5.0 (a version released in 2012) allows XSS via the format parameter to the default URI. NOTE: This vulnerability only affects products that are | Nov 15, 2021 | 6.1 | 30 | NO | YES |
CVE-2013-5032HIGH Unspecified vulnerability in Atmail before 6.6.4, and 7.x before 7.1.2, has unknown impact and attack vectors, a different vulnerability than CVE-2013-5031, CVE-2013-5033, and CVE- | Jan 12, 2014 | 10.0 | 30 | NO | NO |
CVE-2017-9519HIGH atmail before 7.8.0.2 has CSRF, allowing an attacker to create a user account. | Jun 8, 2017 | 8.8 | 27 | NO | NO |
CVE-2017-9518HIGH atmail before 7.8.0.2 has CSRF, allowing an attacker to change the SMTP hostname and hijack all emails. | Jun 8, 2017 | 8.8 | 27 | NO | NO |
CVE-2017-9517HIGH atmail before 7.8.0.2 has CSRF, allowing an attacker to upload and import users via CSV. | Jun 8, 2017 | 8.8 | 27 | NO | NO |
CVE-2022-30776MEDIUM atmail 6.5.0 allows XSS via the index.php/admin/index/ error parameter. | May 16, 2022 | 6.1 | 26 | NO | YES |
CVE-2024-24133CRITICAL Atmail v6.6.0 was discovered to contain a SQL injection vulnerability via the username parameter on the login page. | Feb 7, 2024 | 9.8 | 25 | NO | NO |
CVE-2013-5034HIGH Unspecified vulnerability in Atmail before 6.6.4, and 7.x before 7.1.2, has unknown impact and attack vectors, a different vulnerability than CVE-2013-5031, CVE-2013-5032, and CVE- | Jan 12, 2014 | 10.0 | 25 | NO | NO |
CVE-2013-5033HIGH Unspecified vulnerability in Atmail before 6.6.4, and 7.x before 7.1.2, has unknown impact and attack vectors, a different vulnerability than CVE-2013-5031, CVE-2013-5032, and CVE- | Jan 12, 2014 | 10.0 | 25 | NO | NO |
Signals from CVEs in this vendor scope (32 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Atmail.
Media articles that mention a CVE ID that affects a product developed by Atmail — matched by CVE ID, not by vendor name.