Webcit
Vendor:
First CVE: Jul 17, 2007 · Active for 19 years
9
Total CVEs
More Total CVEs than 86% of tracked products
2.3
Avg CVEs / Year
Higher CVE frequency than 73% of tracked products
6.1
Avg CVSS
Higher Avg CVSS than 21% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Webcit over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 17, 2007
19 years ago
Most Recent CVE
May 29, 2023
1,151 days ago
CVE Severity & Scoring
Webcit9 CVEs
22%
44%
22%
11%
All CVEs352,101 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network6 (66.7%)
Unknown3 (33.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (44.4%)
High2 (22.2%)
Unknown3 (33.3%)
User Interaction
None5 (55.6%)
Unknown3 (33.3%)
Required1 (11.1%)
Privileges Required
Low1 (11.1%)
High0 (0.0%)
None5 (55.6%)
Unknown3 (33.3%)
Top CVEs
Signals from CVEs in this product scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-27739CRITICAL A Weak Session Management vulnerability in Citadel WebCit through 926 allows unauthenticated remote attackers to hijack recently logged-in users' sessions. NOTE: this was reported | Oct 28, 2020 | 9.8 | 24 | NO | NO |
CVE-2007-3821HIGH Cross-site request forgery (CSRF) vulnerability in Webcit before 7.11 allows remote attackers to modify configurations and perform other actions as arbitrary users via unspecified | Jul 17, 2007 | 7.5 | 22 | NO | NO |
CVE-2020-27742MEDIUM An Insecure Direct Object Reference vulnerability in Citadel WebCit through 926 allows authenticated remote attackers to read someone else's emails via the msg_confirm_move templat | Oct 28, 2020 | 6.5 | 21 | NO | NO |
CVE-2020-29547MEDIUM An issue was discovered in Citadel through webcit-926. Meddler-in-the-middle attackers can pipeline commands after POP3 STLS, IMAP STARTTLS, or SMTP STARTTLS commands, injecting cl | May 29, 2023 | 5.9 | 20 | NO | NO |
CVE-2020-27741MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Citadel WebCit through 926 allow remote attackers to inject arbitrary web script or HTML via multiple pages and parameters. N | Oct 28, 2020 | 6.1 | 20 | NO | NO |
CVE-2009-0364HIGH Format string vulnerability in the mini_calendar component in Citadel.org WebCit 7.22, and other versions before 7.39, allows remote attackers to execute arbitrary code via unspeci | Mar 26, 2009 | 7.5 | 20 | NO | NO |
CVE-2020-27740MEDIUM Citadel WebCit through 926 allows unauthenticated remote attackers to enumerate valid users within the platform. NOTE: this was reported to the vendor in a publicly archived "Multi | Oct 28, 2020 | 5.3 | 19 | NO | NO |
Multiple cross-site scripting (XSS) vulnerabilities in Webcit before 7.11 allow remote attackers to inject arbitrary web script or HTML via (1) the who parameter to showuser; and o | Jul 17, 2007 | 2.6 | 18 | NO | YES |
An issue was discovered in Citadel through webcit-932. A meddler-in-the-middle attacker can fixate their own session during the cleartext phase before a STARTTLS command (a violati | May 29, 2023 | 3.7 | 16 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (9 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
11.1% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (9 CVEs).
Media Mentions
Signals from CVEs in this product scope (9 CVEs).
Top CNAs Publishing CVEs For Webcit
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 7.37 | 1 | 7.5 | 2.6% | 0 | 0 |
| 7.22 | 1 | 7.5 | 2.6% | 0 | 0 |
| 7.12 | 1 | 7.5 | 2.6% | 0 | 0 |
| 7.11 | 1 | 7.5 | 2.6% | 0 | 0 |
| 7.10 | 1 | 7.5 | 2.6% | 0 | 0 |
| 7.02 | 1 | 7.5 | 2.6% | 0 | 0 |