Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Modoboa

First CVE: Dec 10, 2019Active for: 7 yearsTotal CVEs: 17
44.5
VTI Score
High

Modoboa is a modestly represented, self-hosted mail and collaboration server platform whose vulnerability profile skews toward serious outcomes with an elevated share reaching critical severity. The exposure concentrates in the core server and installer components and recurs through web-application and access-control weakness classes—cross-site request forgery, cross-site scripting, authentication bypass, improper authorization, and OS command injection—that are characteristic of web-facing mail infrastructure. Live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
17
Total CVEs
More Total CVEs than 95% of tracked vendors
1.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
6.9
Avg CVSS Score
Higher Avg CVSS Score than 49% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Modoboa over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 10, 2019
6 years ago
Most Recent CVE
Jun 29, 2026
26 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (17 CVEs).

17 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-2227CRITICAL
Improper Authorization in GitHub repository modoboa/modoboa prior to 2.1.0.
Apr 21, 20239.166NOYES
CVE-2023-0777CRITICAL
Authentication Bypass by Primary Weakness in GitHub repository modoboa/modoboa prior to 2.0.4.
Feb 10, 20239.850NOYES
CVE-2026-56780HIGH
Modoboa before 2.9.0 contains an insecure direct object reference vulnerability in the PUT /api/v1/accounts/{pk}/password/ endpoint that allows domain administrators to change any
Jun 29, 20267.532NONO
CVE-2023-2160CRITICAL
Weak Password Requirements in GitHub repository modoboa/modoboa prior to 2.1.0.
Apr 18, 20239.830NONO
CVE-2026-27602HIGH
Modoboa is a mail hosting and management platform. Prior to version 2.7.1, `exec_cmd()` in `modoboa/lib/sysutils.py` always runs subprocess calls with `shell=True`. Since domain na
Mar 25, 20267.225NONO
CVE-2023-5690HIGH
Cross-Site Request Forgery (CSRF) in GitHub repository modoboa/modoboa prior to 2.2.2.
Oct 20, 20238.824NONO
CVE-2023-0860HIGH
Improper Restriction of Excessive Authentication Attempts in GitHub repository modoboa/modoboa-installer prior to 2.0.4.
Feb 16, 20237.524NONO
CVE-2019-19702HIGH
The modoboa-dmarc plugin 1.1.0 for Modoboa is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this to perform
Dec 10, 20197.524NONO
CVE-2023-2228MEDIUM
Cross-Site Request Forgery (CSRF) in GitHub repository modoboa/modoboa prior to 2.1.0.
Apr 21, 20236.822NONO
CVE-2023-0398MEDIUM
Cross-Site Request Forgery (CSRF) in GitHub repository modoboa/modoboa prior to 2.0.4.
Jan 19, 20236.522NONO
View all 17 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products17 CVEs
53%
29%
18%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network17 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low16 (94.1%)
High1 (5.9%)
Unknown0 (0.0%)
User Interaction
None7 (41.2%)
Unknown0 (0.0%)
Required10 (58.8%)
Privileges Required
Low5 (29.4%)
High3 (17.6%)
None9 (52.9%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (17 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
11.8% of CVEs· 96th percentile
ExploitDB
1 CVE
5.9% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Modoboa.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Modoboa — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Modoboa's Products

View all 4 CNAs →

Top CWEs