Rainloop is a web-based email client offering self-hosted webmail functionality, and its disclosed vulnerabilities center on cross-site scripting weaknesses in web-page generation and output handling. This reflects the attack surface characteristic of client-side email interfaces where untrusted message content and user input must be safely rendered. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Rainloop over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-13389MEDIUM RainLoop Webmail before 1.13.0 lacks XSS protection mechanisms such as xlink:href validation, the X-XSS-Protection header, and the Content-Security-Policy header. | Mar 20, 2020 | 6.1 | 21 | NO | NO |
CVE-2022-29360MEDIUM The Email Viewer in RainLoop through 1.6.0 allows XSS via a crafted email message. | Jul 28, 2022 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Rainloop.
Media articles that mention a CVE ID that affects a product developed by Rainloop — matched by CVE ID, not by vendor name.