Vendor:
First CVE: May 12, 2020 · Active for 6 years
15
Total CVEs
More Total CVEs than 92% of tracked products
2.5
Avg CVEs / Year
Higher CVE frequency than 74% of tracked products
5.9
Avg CVSS
Higher Avg CVSS than 18% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Mail over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 12, 2020
6 years ago
Most Recent CVE
Dec 5, 2025
231 days ago
CVE Severity & Scoring
Mail15 CVEs
67%
13%
13%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network14 (93.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (6.7%)
Attack Complexity
Low14 (93.3%)
High1 (6.7%)
Unknown0 (0.0%)
User Interaction
None11 (73.3%)
Unknown0 (0.0%)
Required4 (26.7%)
Privileges Required
Low7 (46.7%)
High1 (6.7%)
None7 (46.7%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-31132CRITICAL Nextcloud Mail is an email application for the nextcloud personal cloud product. Affected versions shipped with a CSS minifier on the path `./vendor/cerdic/css-tidy/css_optimiser.p | Aug 4, 2022 | 9.8 | 29 | NO | NO |
CVE-2023-48307CRITICAL Nextcloud Mail is the mail app for Nextcloud, a self-hosted productivity platform. Starting in version 1.13.0 and prior to version 2.2.8 and 3.3.0, an attacker can use an unprotect | Nov 21, 2023 | 9.8 | 28 | NO | NO |
CVE-2020-8156HIGH A missing verification of the TLS host in Nextcloud Mail 1.1.3 allowed a man in the middle attack. | May 12, 2020 | 7.0 | 23 | NO | NO |
CVE-2024-52508HIGH Nextcloud Mail is the mail app for Nextcloud, a self-hosted productivity platform. When a user is trying to set up a mail account with an email address like [email protected] that d | Nov 15, 2024 | 8.1 | 22 | NO | NO |
CVE-2023-23944MEDIUM Nextcloud mail is an email app for the nextcloud home server platform. In versions prior to 2.2.2 user's passwords were stored in cleartext in the database during the duration of O | Feb 6, 2023 | 6.5 | 22 | NO | NO |
CVE-2022-31119MEDIUM Nextcloud Mail is an email application for the nextcloud personal cloud product. Affected versions of Nextcloud mail would log user passwords to disk in the event of a misconfigura | Aug 4, 2022 | 4.9 | 19 | NO | NO |
CVE-2025-66514MEDIUM Nextcloud Mail is the mail app for Nextcloud, a self-hosted productivity platform. Prior to 5.5.3, a stored HTML injection in the Mail app's message list allowed an authenticated u | Dec 5, 2025 | 5.4 | 18 | NO | NO |
CVE-2023-25160MEDIUM Nextcloud Mail is an email app for the Nextcloud home server platform. Prior to versions 2.2.1, 1.14.5, 1.12.9, and 1.11.8, an attacker can access the mail box by ID getting the su | Feb 13, 2023 | 5.3 | 18 | NO | NO |
CVE-2024-52509MEDIUM Nextcloud Mail is the mail app for Nextcloud, a self-hosted productivity platform. The Nextcloud mail app incorrectly allowed attaching shared files without download permissions as | Nov 15, 2024 | 5.7 | 17 | NO | NO |
CVE-2023-23943MEDIUM Nextcloud mail is an email app for the nextcloud home server platform. In affected versions the SMTP, IMAP and Sieve host fields allowed to scan for internal services and servers r | Feb 6, 2023 | 4.3 | 17 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (15 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (15 CVEs).
Media Mentions
Signals from CVEs in this product scope (15 CVEs).
Top CNAs Publishing CVEs For Mail
Top CWEs
Versions
No cataloged versions.