Mail Server
Vendor:
First CVE: Sep 30, 2011 · Active for 14 years
19
Total CVEs
More Total CVEs than 93% of tracked products
2.7
Avg CVEs / Year
Higher CVE frequency than 75% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 29% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Mail Server over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 30, 2011
14 years ago
Most Recent CVE
May 16, 2025
435 days ago
CVE Severity & Scoring
Mail Server19 CVEs
79%
16%
All CVEs352,427 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network17 (89.5%)
Unknown2 (10.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low17 (89.5%)
High0 (0.0%)
Unknown2 (10.5%)
User Interaction
None6 (31.6%)
Unknown2 (10.5%)
Required11 (57.9%)
Privileges Required
Low4 (21.1%)
High1 (5.3%)
None12 (63.2%)
Unknown2 (10.5%)
Top CVEs
Signals from CVEs in this product scope (19 CVEs).
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-1503HIGH Multiple directory traversal vulnerabilities in IceWarp Mail Server before 11.2 allow remote attackers to read arbitrary files via a (1) .. (dot dot) in the file parameter to a web | May 8, 2018 | 7.5 | 69 | NO | YES |
CVE-2019-12593HIGH IceWarp Mail Server through 10.4.4 is prone to a local file inclusion vulnerability via webmail/calendar/minimizer/index.php?style=..%5c directory traversal. | Jun 3, 2019 | 7.5 | 65 | NO | YES |
CVE-2020-27982MEDIUM IceWarp 11.4.5.0 allows XSS via the language parameter. | Nov 2, 2020 | 6.1 | 32 | NO | YES |
CVE-2021-36580MEDIUM Open Redirect vulnerability exists in IceWarp MailServer IceWarp Server Deep Castle 2 Update 1 (13.0.1.2) via the referer parameter. | Jul 27, 2023 | 6.1 | 31 | NO | YES |
CVE-2011-3579MEDIUM server/webmail.php in IceWarp WebMail in IceWarp Mail Server before 10.3.3 allows remote attackers to read arbitrary files, and possibly send HTTP requests to intranet servers or c | Sep 30, 2011 | 6.4 | 31 | NO | YES |
CVE-2020-14066HIGH IceWarp Email Server 12.3.0.1 allows remote attackers to upload JavaScript files that are dangerous for clients to access. | Jul 15, 2020 | 8.8 | 28 | NO | NO |
CVE-2023-39700MEDIUM IceWarp Mail Server v10.4.5 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the color parameter. | Aug 25, 2023 | 6.1 | 25 | NO | YES |
CVE-2023-39699CRITICAL IceWarp Mail Server v10.4.5 was discovered to contain a local file inclusion (LFI) vulnerability via the component /calendar/minimizer/index.php. This vulnerability allows attacker | Aug 25, 2023 | 9.8 | 25 | NO | NO |
CVE-2025-40630MEDIUM Open redirection vulnerability in IceWarp Mail Server affecting version 11.4.0. This vulnerability allows an attacker to redirect a user to any domain by sending a malicious URL to | May 16, 2025 | 6.1 | 24 | NO | YES |
CVE-2020-14064MEDIUM IceWarp Email Server 12.3.0.1 has Incorrect Access Control for user accounts. | Jul 15, 2020 | 6.5 | 22 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (19 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
6 CVEs
31.6% of CVEs· 98th percentile
ExploitDB
3 CVEs
15.8% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (19 CVEs).
Media Mentions
Signals from CVEs in this product scope (19 CVEs).
Top CNAs Publishing CVEs For Mail Server
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.4.2 | 2 | 5.7 | 3.2% | 0 | 1 |
| 9.4.1 | 2 | 5.7 | 3.2% | 0 | 1 |
| 9.4.0 | 2 | 5.7 | 3.2% | 0 | 1 |
| 9.3.2 | 2 | 5.7 | 3.2% | 0 | 1 |
| 9.3.1 | 2 | 5.7 | 3.2% | 0 | 1 |
| 9.3.0 | 2 | 5.7 | 3.2% | 0 | 1 |
| 12.3.0.1 | 3 | 7.3 | 1.4% | 0 | 0 |
| 12.0.3 | 1 | 6.1 | 1.0% | 0 | 0 |
| 11.4.5 | 1 | 6.1 | 5.3% | 0 | 1 |
| 11.4.0 | 3 | 6.1 | 0.3% | 0 | 1 |
| 10.4.5 | 2 | 8.0 | 1.3% | 0 | 1 |
| 10.4.4 | 1 | 4.8 | 0.8% | 0 | 0 |
| 10.3.1 | 2 | 5.7 | 3.2% | 0 | 1 |
| 10.3.0 | 2 | 5.7 | 3.2% | 0 | 1 |
| 10.2.2 | 2 | 5.7 | 3.2% | 0 | 1 |
| 10.2.1 | 2 | 5.7 | 3.2% | 0 | 1 |
| 10.2.0 | 2 | 5.7 | 3.2% | 0 | 1 |
| 10.1.4 | 2 | 5.7 | 3.2% | 0 | 1 |
| 10.1.3 | 2 | 5.7 | 3.2% | 0 | 1 |
| 10.1.2 | 2 | 5.7 | 3.2% | 0 | 1 |