Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Citadel

First CVE: Jul 26, 2002Active for: 24 yearsTotal CVEs: 16
36.1
VTI Score
Medium

Citadel is a modestly represented open-source groupware and messaging platform whose vulnerability footprint concentrates in its web-facing components and SMTP service. The recurring weakness classes—primarily cross-site scripting, command injection, and authorization bypass flaws—reflect the input-handling and access-control demands of web and mail infrastructure, while public exploit code frequently emerges for disclosed issues. Live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
16
Total CVEs
More Total CVEs than 95% of tracked vendors
0.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 4% of tracked vendors
6.2
Avg CVSS Score
Higher Avg CVSS Score than 36% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Citadel over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 26, 2002
23 years ago
Most Recent CVE
Oct 4, 2023
1,024 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (16 CVEs).

16 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2004-1192HIGH
Format string vulnerability in the lprintf function in Citadel/UX 6.27 and earlier allows remote attackers to execute arbitrary code via format string specifiers sent to the server
Jan 10, 200510.047NOYES
CVE-2008-0394HIGH
Buffer overflow in Citadel SMTP server 7.10 and earlier allows remote attackers to execute arbitrary code via a long RCPT TO command, which is not properly handled by the makeuserk
Jan 23, 20087.533NOYES
CVE-2002-0432HIGH
Buffer overflow in (1) lprintf and (2) cprintf in sysdep.c of Citadel/UX 5.90 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrar
Jul 26, 200210.032NONO
CVE-2020-27739CRITICAL
A Weak Session Management vulnerability in Citadel WebCit through 926 allows unauthenticated remote attackers to hijack recently logged-in users' sessions. NOTE: this was reported
Oct 28, 20209.824NONO
CVE-2004-1705MEDIUM
Buffer overflow in Citadel/UX 6.23 and earlier allows remote attackers to cause a denial of service via a long username.
Jul 30, 20045.024NOYES
CVE-2007-3821HIGH
Cross-site request forgery (CSRF) vulnerability in Webcit before 7.11 allows remote attackers to modify configurations and perform other actions as arbitrary users via unspecified
Jul 17, 20077.522NONO
CVE-2020-27742MEDIUM
An Insecure Direct Object Reference vulnerability in Citadel WebCit through 926 allows authenticated remote attackers to read someone else's emails via the msg_confirm_move templat
Oct 28, 20206.521NONO
CVE-2020-29547MEDIUM
An issue was discovered in Citadel through webcit-926. Meddler-in-the-middle attackers can pipeline commands after POP3 STLS, IMAP STARTTLS, or SMTP STARTTLS commands, injecting cl
May 29, 20235.920NONO
CVE-2020-27741MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in Citadel WebCit through 926 allow remote attackers to inject arbitrary web script or HTML via multiple pages and parameters. N
Oct 28, 20206.120NONO
CVE-2009-0364HIGH
Format string vulnerability in the mini_calendar component in Citadel.org WebCit 7.22, and other versions before 7.39, allows remote attackers to execute arbitrary code via unspeci
Mar 26, 20097.520NONO
View all 16 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products16 CVEs
19%
44%
31%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network7 (43.8%)
Unknown9 (56.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (31.3%)
High2 (12.5%)
Unknown9 (56.3%)
User Interaction
None5 (31.3%)
Unknown9 (56.3%)
Required2 (12.5%)
Privileges Required
Low2 (12.5%)
High0 (0.0%)
None5 (31.3%)
Unknown9 (56.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (16 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
25.0% of CVEs· 78th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Citadel.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Citadel — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Citadel's Products

View all 3 CNAs →

Top CWEs