Mail Server

Vendor:

First CVE: Sep 30, 2011 · Active for 14 years

19
Total CVEs
More Total CVEs than 93% of tracked products
2.7
Avg CVEs / Year
Higher CVE frequency than 75% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 29% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Mail Server over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 30, 2011
14 years ago
Most Recent CVE
May 16, 2025
435 days ago

CVE Severity & Scoring

Mail Server19 CVEs
All CVEs352,427 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network17 (89.5%)
Unknown2 (10.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low17 (89.5%)
High0 (0.0%)
Unknown2 (10.5%)
User Interaction
None6 (31.6%)
Unknown2 (10.5%)
Required11 (57.9%)
Privileges Required
Low4 (21.1%)
High1 (5.3%)
None12 (63.2%)
Unknown2 (10.5%)

Top CVEs

Signals from CVEs in this product scope (19 CVEs).

19 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Multiple directory traversal vulnerabilities in IceWarp Mail Server before 11.2 allow remote attackers to read arbitrary files via a (1) .. (dot dot) in the file parameter to a web
May 8, 20187.569NOYES
IceWarp Mail Server through 10.4.4 is prone to a local file inclusion vulnerability via webmail/calendar/minimizer/index.php?style=..%5c directory traversal.
Jun 3, 20197.565NOYES
IceWarp 11.4.5.0 allows XSS via the language parameter.
Nov 2, 20206.132NOYES
Open Redirect vulnerability exists in IceWarp MailServer IceWarp Server Deep Castle 2 Update 1 (13.0.1.2) via the referer parameter.
Jul 27, 20236.131NOYES
server/webmail.php in IceWarp WebMail in IceWarp Mail Server before 10.3.3 allows remote attackers to read arbitrary files, and possibly send HTTP requests to intranet servers or c
Sep 30, 20116.431NOYES
IceWarp Email Server 12.3.0.1 allows remote attackers to upload JavaScript files that are dangerous for clients to access.
Jul 15, 20208.828NONO
IceWarp Mail Server v10.4.5 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the color parameter.
Aug 25, 20236.125NOYES
IceWarp Mail Server v10.4.5 was discovered to contain a local file inclusion (LFI) vulnerability via the component /calendar/minimizer/index.php. This vulnerability allows attacker
Aug 25, 20239.825NONO
Open redirection vulnerability in IceWarp Mail Server affecting version 11.4.0. This vulnerability allows an attacker to redirect a user to any domain by sending a malicious URL to
May 16, 20256.124NOYES
IceWarp Email Server 12.3.0.1 has Incorrect Access Control for user accounts.
Jul 15, 20206.522NONO

Exploit Exposure

Signals from CVEs in this product scope (19 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
6 CVEs
31.6% of CVEs· 98th percentile
ExploitDB
3 CVEs
15.8% of CVEs· 89th percentile

Social Chatter

Signals from CVEs in this product scope (19 CVEs).

Media Mentions

Signals from CVEs in this product scope (19 CVEs).

Top CNAs Publishing CVEs For Mail Server

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.4.225.73.2%01
9.4.125.73.2%01
9.4.025.73.2%01
9.3.225.73.2%01
9.3.125.73.2%01
9.3.025.73.2%01
12.3.0.137.31.4%00
12.0.316.11.0%00
11.4.516.15.3%01
11.4.036.10.3%01
10.4.528.01.3%01
10.4.414.80.8%00
10.3.125.73.2%01
10.3.025.73.2%01
10.2.225.73.2%01
10.2.125.73.2%01
10.2.025.73.2%01
10.1.425.73.2%01
10.1.325.73.2%01
10.1.225.73.2%01