Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Smartertools

First CVE: Dec 31, 2004Active for: 22 yearsTotal CVEs: 53
61.8
VTI Score
TOP TARGET

Smartertools develops a focused suite of email, analytics, and tracking products that, while narrow in product count, achieve significant deployment across small and mid-market organizations and managed service providers. Vulnerabilities affecting the vendor skew toward serious outcomes—a meaningful share reach critical severity—and have an elevated tendency toward both confirmed in-the-wild exploitation and public exploit availability, reflecting the internet-facing and business-critical nature of messaging and analytics platforms. The exposure recurs across flagship products such as SmarterMail, SmarterStats, and SmarterTrack through weakness classes including cross-site scripting, path traversal, improper input validation, and sensitive information disclosure—patterns characteristic of web application design at scale. Defenders should treat updates to this vendor's email and analytics products as high-priority given their role in business communication and customer-facing operations; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
53
Total CVEs
More Total CVEs than 99% of tracked vendors
1.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 74% of tracked vendors
6.5
Avg CVSS Score
Higher Avg CVSS Score than 39% of tracked vendors
5.7%
In CISA KEV
Higher KEV Rate than 100% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Smartertools over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2004
21 years ago
Most Recent CVE
May 8, 2026
77 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (53 CVEs).

53 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-24423CRITICAL
SmarterTools SmarterMail versions prior to build 9511 contain an unauthenticated remote code execution vulnerability in the ConnectToHub API method. The attacker could point the Sm
Jan 23, 20269.898YESYES
CVE-2026-23760CRITICAL
SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API. The force-reset-password endpoint permits anonymous
Jan 22, 20269.898YESYES
CVE-2025-52691CRITICAL
Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code
Dec 29, 202510.098YESYES
CVE-2019-7214CRITICAL
SmarterTools SmarterMail 16.x before build 6985 allows deserialization of untrusted data. An unauthenticated attacker could run commands on the server when port 17001 was remotely
Apr 24, 20199.888NOYES
CVE-2019-7213MEDIUM
SmarterTools SmarterMail 16.x before build 6985 allows directory traversal. An authenticated user could delete arbitrary files or could create files in new folders in arbitrary loc
Apr 24, 20196.536NONO
CVE-2026-7807HIGH
SmarterTools SmarterMail builds prior to 9560 contain a local file inclusion vulnerability in the /api/v1/report/summary/{type} API endpoint that allows authenticated users to read
May 8, 20268.833NONO
CVE-2026-40514CRITICAL
SmarterTools SmarterMail builds prior to 9610 contain a cryptographic weakness in the file and email sharing endpoints that use DES-CBC encryption with keys and initialization vect
Apr 27, 20269.132NONO
CVE-2021-32234CRITICAL
SmarterTools SmarterMail 16.x through 100.x before 100.0.7803 allows remote code execution.
Nov 17, 20219.830NONO
CVE-2017-14620MEDIUM
SmarterStats Version 11.3.6347 will Render the Referer Field of HTTP Logfiles from URL /Data/Reports/ReferringURLsWithQueries resulting in Stored Cross Site Scripting.
Sep 30, 20176.130NOYES
CVE-2011-2159HIGH
The SmarterTools SmarterStats 6.0 web server omits the Content-Type header for certain resources, which might allow remote attackers to have an unspecified impact by leveraging an
May 20, 201110.030NONO
View all 53 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products53 CVEs
66%
23%
11%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network26 (49.1%)
Unknown27 (50.9%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low25 (47.2%)
High1 (1.9%)
Unknown27 (50.9%)
User Interaction
None15 (28.3%)
Unknown27 (50.9%)
Required11 (20.8%)
Privileges Required
Low7 (13.2%)
High1 (1.9%)
None18 (34.0%)
Unknown27 (50.9%)

Exploit Exposure

Signals from CVEs in this vendor scope (53 CVEs).

CISA KEV
3 CVEs
5.7% of CVEs· 100th percentile
Metasploit
2 CVEs
3.8% of CVEs· 98th percentile
Nuclei
4 CVEs
7.5% of CVEs· 96th percentile
ExploitDB
7 CVEs
13.2% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Smartertools.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Smartertools — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Smartertools's Products

View all 5 CNAs →

Top CWEs