Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Rakuten

First CVE: Jun 3, 2019Active for: 7 yearsTotal CVEs: 12
36.6
VTI Score
Medium

Rakuten's vulnerability footprint centers on a diverse consumer-facing portfolio spanning messaging, e-commerce, and connectivity services, with a modest disclosure history concentrated around products such as Viber, Casa, Ichiba, Rakuma, and WiFi Pocket. Vulnerabilities affecting the vendor skew toward serious outcomes and recur through durable weakness classes including cleartext transmission of sensitive data, improper authentication and authorization mechanisms, and exposure of sensitive information—patterns characteristic of applications handling user credentials and personal data. Defenders tracking this vendor should focus on mobile and cloud-connected services where authentication and data-protection issues carry elevated user-privacy impact; current severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
12
Total CVEs
More Total CVEs than 93% of tracked vendors
0.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 3% of tracked vendors
7.3
Avg CVSS Score
Higher Avg CVSS Score than 55% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Rakuten over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 3, 2019
7 years ago
Most Recent CVE
Mar 5, 2026
141 days ago

Products(6 total)

Top CVEs

Signals from CVEs in this vendor scope (12 CVEs).

12 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-13476CRITICAL
Rakuten Viber Cloak mode in Android v25.7.2.0g and Windows v25.6.0.0–v25.8.1.0 uses a static and predictable TLS ClientHello fingerprint lacking extension diversity, allowing Deep
Mar 5, 20269.832NONO
CVE-2019-12569HIGH
A vulnerability in Viber before 10.7.0 for Desktop (Windows) could allow an attacker to execute arbitrary commands on a targeted system. This vulnerability is due to unsafe search
Jun 3, 20197.832NONO
CVE-2022-29525CRITICAL
Rakuten Casa version AP_F_V1_4_1 or AP_F_V2_0_0 uses a hard-coded credential which may allow a remote unauthenticated attacker to log in with the root privilege and perform an arbi
Jun 13, 20229.831NONO
CVE-2019-18800HIGH
Viber through 11.7.0.5 allows a remote attacker who can capture a victim's internet traffic to steal their Viber account, because not all Viber protocol traffic is encrypted. TCP d
Nov 6, 20198.828NONO
CVE-2022-26834HIGH
Improper access control vulnerability in Rakuten Casa version AP_F_V1_4_1 or AP_F_V2_0_0 allows a remote attacker to obtain the information stored in the product because the produc
Jun 13, 20227.525NONO
CVE-2020-14049HIGH
Viber for Windows up to 13.2.0.39 does not properly quote its custom URI handler. A malicious website could launch Viber with arbitrary parameters, forcing a victim to send an NTLM
Jun 22, 20207.524NONO
CVE-2019-6024MEDIUM
Rakuma App for Android version 7.15.0 and earlier, and for iOS version 7.16.4 and earlier allows an attacker to bypass authentication and obtain the user's authentication informati
Dec 26, 20196.522NONO
CVE-2025-55996MEDIUM
Viber Desktop 25.6.0 is vulnerable to HTML Injection via the text parameter of the message compose/forward interface
Sep 12, 20256.321NONO
CVE-2024-41918MEDIUM
'Rakuten Ichiba App' for Android 12.4.0 and earlier and 'Rakuten Ichiba App' for iOS 11.7.0 and earlier are vulnerable to improper authorization in handler for custom URL scheme. A
Aug 29, 20246.119NONO
CVE-2022-28704HIGH
Improper access control vulnerability in Rakuten Casa version AP_F_V1_4_1 or AP_F_V2_0_0 allows a remote attacker to log in with the root privilege and perform an arbitrary operati
Jun 13, 20227.219NONO
View all 12 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products12 CVEs
42%
42%
17%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local2 (16.7%)
Network9 (75.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (8.3%)
Attack Complexity
Low12 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None7 (58.3%)
Unknown0 (0.0%)
Required5 (41.7%)
Privileges Required
Low1 (8.3%)
High1 (8.3%)
None10 (83.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (12 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Rakuten.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Rakuten — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Rakuten's Products

View all 4 CNAs →

Top CWEs