Ciphermail develops email security and messaging gateway products, with a narrow but strategically positioned product line centered on webmail and gateway appliances that handle message encryption and authentication. The observed vulnerability pattern centers on access-control and cryptographic configuration issues—improper privilege management, inadequate encryption strength, and incorrect default permissions—reflecting the sensitivity of email infrastructure and the criticality of proper secrets and permission enforcement in messaging systems. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ciphermail over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-28218MEDIUM An issue was discovered in CipherMail Webmail Messenger 1.1.1 through 4.1.4. A local attacker could access secret keys (found in a Roundcube configuration file) that are used to pr | Apr 26, 2022 | 5.5 | 20 | NO | NO |
CVE-2020-12713HIGH An issue was discovered in CipherMail Community Gateway and Professional/Enterprise Gateway 1.0.1 through 4.7.1-0 and CipherMail Webmail Messenger 1.1.1 through 3.1.1-0. Attackers | Jun 11, 2020 | 7.2 | 19 | NO | NO |
CVE-2020-12714MEDIUM An issue was discovered in CipherMail Community Gateway Virtual Appliances and Professional/Enterprise Gateway Virtual Appliances versions 1.0.1 through 4.7.1-0 and CipherMail Webm | Jun 11, 2020 | 5.9 | 16 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ciphermail.
Media articles that mention a CVE ID that affects a product developed by Ciphermail — matched by CVE ID, not by vendor name.