Communigate develops email and messaging server software, primarily through its Communigate Pro product line, with a vulnerability footprint centered on web-facing server components. The durable signal in observed disclosures reflects input-handling and cross-site scripting weaknesses typical of web-accessible messaging interfaces; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Communigate over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-16962MEDIUM The WebMail components (Crystal, pronto, and pronto4) in CommuniGate Pro before 6.2.1 have stored XSS vulnerabilities via (1) the location or details field of a Google Calendar inv | Nov 27, 2017 | 6.1 | 30 | NO | YES |
CVE-2018-18621MEDIUM CommuniGate Pro 6.2 allows stored XSS via a message body in Pronto! Mail Composer, which is mishandled in /MIME/INBOX-MM-1/ if the raw email link (in .txt format) is modified and t | Oct 24, 2018 | 6.1 | 21 | NO | NO |
CVE-2006-0566MEDIUM The LDAP component in CommuniGate Pro Core Server 5.0.7 allows remote attackers to cause a denial of service (application crash) via LDAP messages that contain Distinguished Names | Feb 6, 2006 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Communigate.
Media articles that mention a CVE ID that affects a product developed by Communigate — matched by CVE ID, not by vendor name.