Tuta maintains a focused encrypted email and productivity platform under the Tutanota product name, a niche offering in secure communications with a correspondingly narrow vulnerability footprint. The durable signal from disclosed vulnerabilities centers on web application input handling and server-side request forgery, weakness classes typical of internet-facing communication services. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tuta over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-46116HIGH Tutanota (Tuta Mail) is an encrypted email provider. Tutanota allows users to open links in emails in external applications. Prior to version 3.118.12, it correctly blocks the `fil | Dec 15, 2023 | 8.8 | 22 | NO | NO |
CVE-2024-23655MEDIUM Tuta is an encrypted email service. Starting in version 3.118.12 and prior to version 3.119.10, an attacker is able to send a manipulated email so that the user can no longer use t | Jan 25, 2024 | 5.3 | 17 | NO | NO |
CVE-2024-23330MEDIUM Tuta is an encrypted email service. In versions prior to 119.10, an attacker can attach an image in a html mail which is loaded from external resource in the default setting, which | Jan 23, 2024 | 5.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tuta.
Media articles that mention a CVE ID that affects a product developed by Tuta — matched by CVE ID, not by vendor name.