VYPR

Icewarp

by IceWarp

CVEs (11)

  • CVE-2025-14500CriDec 23, 2025
    risk 0.64cvss 9.8epss 0.01

    IceWarp14 X-File-Operation Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of IceWarp. Authentication is not required to exploit this vulnerability. The specific flaw exists…

  • CVE-2025-14499HigDec 23, 2025
    risk 0.57cvss 8.8epss 0.01

    IceWarp gmaps Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of IceWarp. User interaction is required to exploit this vulnerability in that the target must visit a malicious…

  • CVE-2019-12593HigJun 3, 2019
    risk 0.55cvss 7.5epss 0.41

    IceWarp Mail Server through 10.4.4 is prone to a local file inclusion vulnerability via webmail/calendar/minimizer/index.php?style=..%5c directory traversal.

  • CVE-2026-2493HigMar 16, 2026
    risk 0.49cvss 7.5epss 0.04

    IceWarp collaboration Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of IceWarp. Authentication is not required to exploit this vulnerability. The specific flaw…

  • CVE-2018-25269MedApr 22, 2026
    risk 0.40cvss 6.1epss 0.00

    ICEWARP 10.3.4 and 11.0.0.0 contains a cross-site scripting vulnerability that allows attackers to inject malicious HTML elements into emails by embedding base64-encoded payloads in object and embed tags. Attackers can craft emails containing data URIs with embedded scripts that…

  • CVE-2025-40630MedMay 16, 2025
    risk 0.40cvss 6.1epss 0.00

    Open redirection vulnerability in IceWarp Mail Server affecting version 11.4.0. This vulnerability allows an attacker to redirect a user to any domain by sending a malicious URL to the victim, for example “ https://icewarp.domain.com//<MALICIOUS_DOMAIN>/%2e%2e”…

  • CVE-2024-55218MedJan 7, 2025
    risk 0.40cvss 6.1epss 0.01

    IceWarp Server 10.2.1 is vulnerable to Cross Site Scripting (XSS) via the meta parameter.

  • CVE-2023-41013MedSep 12, 2023
    risk 0.40cvss 6.1epss 0.00

    Cross Site Scripting (XSS) in Webmail Calendar in IceWarp 10.3.1 allows remote attackers to inject arbitrary web script or HTML via the "p4" field.

  • CVE-2023-39600MedAug 25, 2023
    risk 0.40cvss 6.1epss 0.01

    IceWarp 11.4.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the color parameter.

  • CVE-2023-37728MedJul 20, 2023
    risk 0.40cvss 6.1epss 0.01

    IceWarp v10.2.1 was discovered to contain cross-site scripting (XSS) vulnerability via the color parameter.

  • CVE-2024-0246MedJan 5, 2024
    risk 0.28cvss 4.3epss 0.00

    A vulnerability classified as problematic has been found in IceWarp 12.0.2.1/12.0.3.1. This affects an unknown part of the file /install/ of the component Utility Download Handler. The manipulation of the argument lang with the input 1%27"()%26%25alert(document.domai…