Icewarp
Icewarp: vulnerabilidades y CVE
Icewarp tiene 9 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE9
Últimos 12 meses4
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2018-25269 | Media (5.1) | 0.23% | — | 22 abr 2026 | ICEWARP 10.3.4 and 11.0.0.0 contains a cross-site scripting vulnerability that allows attackers to inject malicious HTML elements into emails by embedding base64-encoded payloads in object and embed tags. Attackers can… |
| CVE-2026-2493 | Alta (7.5) | 3.9% | — | 16 mar 2026 | IceWarp collaboration Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of IceWarp. Authentication is not… |
| CVE-2025-14500 | Crítica (9.8) | 1.5% | — | 23 dic 2025 | IceWarp14 X-File-Operation Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of IceWarp. Authentication is not required… |
| CVE-2025-14499 | Alta (8.8) | 0.87% | — | 23 dic 2025 | IceWarp gmaps Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of IceWarp. User interaction is required to exploit… |
| CVE-2024-55218 | Media (6.1) | 0.70% | — | 7 ene 2025 | IceWarp Server 10.2.1 is vulnerable to Cross Site Scripting (XSS) via the meta parameter. |
| CVE-2024-0246 | Media (6.1) | 0.39% | — | 5 ene 2024 | A vulnerability classified as problematic has been found in IceWarp 12.0.2.1/12.0.3.1. This affects an unknown part of the file /install/ of the component Utility Download Handler. The manipulation of the argument lang… |
| CVE-2023-41013 | Media (6.1) | 0.60% | — | 12 sept 2023 | Cross Site Scripting (XSS) in Webmail Calendar in IceWarp 10.3.1 allows remote attackers to inject arbitrary web script or HTML via the "p4" field. |
| CVE-2023-39600 | Media (6.1) | 1.2% | — | 25 ago 2023 | IceWarp 11.4.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the color parameter. |
| CVE-2023-37728 | Media (6.1) | 1.2% | — | 20 jul 2023 | IceWarp v10.2.1 was discovered to contain cross-site scripting (XSS) vulnerability via the color parameter. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.