Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Lotus

First CVE: May 4, 1999Active for: 27 yearsTotal CVEs: 31
32.4
VTI Score
Medium

Lotus's vulnerability footprint centers on its Domino messaging and collaboration server platform, a long-lived enterprise product family that has accumulated disclosures spanning multiple major versions and deployment contexts. The vendor's exposure recurs through information-disclosure and data-exposure weakness classes, reflecting the sensitive nature of mail and directory data resident on these systems and the attack surface presented by their administrative interfaces and protocol handlers. While the absolute severity profile remains modest, vulnerabilities affecting Domino have an elevated tendency to attract public exploit code, making timely patching operationally important despite lower critical-severity prevalence. Defenders should maintain inventory of Domino deployments by version and treat disclosures in this product line as requiring prompt evaluation; current exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
31
Total CVEs
More Total CVEs than 97% of tracked vendors
0.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 10% of tracked vendors
6.1
Avg CVSS Score
Higher Avg CVSS Score than 30% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Lotus over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 4, 1999
27 years ago
Most Recent CVE
Oct 21, 2011
5,390 days ago

Products(8 total)

Top CVEs

Signals from CVEs in this vendor scope (31 CVEs).

31 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2001-0846HIGH
Lotus Domino 5.x allows remote attackers to read files or execute arbitrary code by requesting the ReplicaID of the Web Administrator template file (webadmin.ntf).
Dec 6, 200110.046NONO
CVE-2000-1046HIGH
Multiple buffer overflows in the ESMTP service of Lotus Domino 5.0.2c and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via long (
Dec 11, 200010.037NOYES
CVE-2001-0009MEDIUM
Directory traversal vulnerability in Lotus Domino 5.0.5 web server allows remote attackers to read arbitrary files via a .. attack.
Feb 12, 20015.032NOYES
CVE-2000-1047HIGH
Buffer overflow in SMTP service of Lotus Domino 5.0.4 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long ENVID keyw
Dec 11, 200010.026NONO
CVE-2001-0130HIGH
Buffer overflow in HTML parser of the Lotus R5 Domino Server before 5.06, and Domino Client before 5.05, allows remote attackers to cause a denial of service and possibly execute a
Mar 12, 200110.025NONO
CVE-2000-0452MEDIUM
Buffer overflow in the ESMTP service of Lotus Domino Server 5.0.1 allows remote attackers to cause a denial of service via a long MAIL FROM command.
May 18, 20005.025NOYES
CVE-2002-2191MEDIUM
Lotus Domino 5.0.9a and earlier, even when configured with the 'DominoNoBanner=1' option, allows remote attackers to obtain potential sensitive information such as the version via
Dec 31, 20025.023NOYES
CVE-2011-0290MEDIUM
The BlackBerry Collaboration Service in Research In Motion (RIM) BlackBerry Enterprise Server (BES) 5.0.3 through MR4 for Microsoft Exchange and Lotus Domino allows remote authenti
Oct 21, 20116.521NONO
CVE-2002-0407MEDIUM
htcgibin.exe in Lotus Domino server 5.0.9a and earlier allows remote attackers to determine the physical pathname for the server via requests that contain certain MS-DOS device nam
Jul 26, 20025.020NONO
CVE-2002-0245HIGH
Lotus Domino server 5.0.8 with NoBanner enabled allows remote attackers to (1) determine the physical path of the server via a request for a nonexistent file with a .pl (Perl) exte
May 29, 20027.520NONO
View all 31 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products31 CVEs
65%
32%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown31 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown31 (100.0%)
User Interaction
None0 (0.0%)
Unknown31 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown31 (100.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (31 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
12.9% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Lotus.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Lotus — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Lotus's Products

View all 1 CNAs →

Top CWEs