Icewarp develops a focused suite of email and web-communication products—including webmail clients, mail servers, and web interfaces—that sit in the messaging infrastructure of small to medium-sized deployments. The vendor's vulnerability footprint is well-represented in the landscape and exhibits a durable pattern of public exploit availability, concentrated in web-facing and application-layer components. Recurring weakness classes include cross-site scripting, path traversal, open redirects, and SQL injection, reflecting the input-validation and URL-handling demands of browser-based mail clients and web interfaces. These vulnerabilities are typical of messaging and collaboration software where user-controlled input crosses authentication and output boundaries; defenders should prioritize web-tier patching and input sanitization for exposed Icewarp instances. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Icewarp over time
Signals from CVEs in this vendor scope (70 CVEs).
70 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-1503HIGH Multiple directory traversal vulnerabilities in IceWarp Mail Server before 11.2 allow remote attackers to read arbitrary files via a (1) .. (dot dot) in the file parameter to a web | May 8, 2018 | 7.5 | 69 | NO | YES |
CVE-2019-12593HIGH IceWarp Mail Server through 10.4.4 is prone to a local file inclusion vulnerability via webmail/calendar/minimizer/index.php?style=..%5c directory traversal. | Jun 3, 2019 | 7.5 | 65 | NO | YES |
CVE-2020-8512MEDIUM In IceWarp Webmail Server through 11.4.4.1, there is XSS in the /webmail/ color parameter. | Feb 1, 2020 | 6.1 | 47 | NO | YES |
CVE-2020-27982MEDIUM IceWarp 11.4.5.0 allows XSS via the language parameter. | Nov 2, 2020 | 6.1 | 32 | NO | YES |
CVE-2005-4556HIGH PHP remote file include vulnerability in IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, when register_globals is enable | Dec 28, 2005 | 7.5 | 32 | NO | YES |
CVE-2021-36580MEDIUM Open Redirect vulnerability exists in IceWarp MailServer IceWarp Server Deep Castle 2 Update 1 (13.0.1.2) via the referer parameter. | Jul 27, 2023 | 6.1 | 31 | NO | YES |
CVE-2011-3579MEDIUM server/webmail.php in IceWarp WebMail in IceWarp Mail Server before 10.3.3 allows remote attackers to read arbitrary files, and possibly send HTTP requests to intranet servers or c | Sep 30, 2011 | 6.4 | 31 | NO | YES |
CVE-2022-35115CRITICAL IceWarp WebClient DC2 - Update 2 Build 9 (13.0.2.9) was discovered to contain a SQL injection vulnerability via the search parameter at /webmail/server/webmail.php. | Aug 23, 2022 | 9.8 | 30 | NO | NO |
CVE-2017-7855MEDIUM In the webmail component in IceWarp Server 11.3.1.5, there was an XSS vulnerability discovered in the "language" parameter. | Aug 31, 2017 | 6.1 | 30 | NO | YES |
CVE-2023-37728MEDIUM IceWarp v10.2.1 was discovered to contain cross-site scripting (XSS) vulnerability via the color parameter. | Jul 20, 2023 | 6.1 | 29 | NO | YES |
Signals from CVEs in this vendor scope (70 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Icewarp.
Media articles that mention a CVE ID that affects a product developed by Icewarp — matched by CVE ID, not by vendor name.