iRedmail develops a focused open-source mail server and administration platform where disclosed vulnerabilities center on web-application input handling, particularly cross-site scripting in the web interface and improper permission assignment in critical administrative resources. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Iredmail over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-1000072HIGH iRedMail version prior to commit f04b8ef contains a Insecure Permissions vulnerability in Roundcube Webmail that can result in Exfiltrate a user's password protected secret GPG key | Mar 13, 2018 | 7.5 | 23 | NO | NO |
CVE-2024-47227MEDIUM iRedAdmin before 2.6 allows XSS, e.g., via order_name. | Sep 23, 2024 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Iredmail.
Media articles that mention a CVE ID that affects a product developed by Iredmail — matched by CVE ID, not by vendor name.