« Volver al listado

Icewarp

Icewarp: vulnerabilidades y CVE

Icewarp tiene 9 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE9
Últimos 12 meses4
Críticas1
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2018-25269Media (5.1)0.23%—22 abr 2026
ICEWARP 10.3.4 and 11.0.0.0 contains a cross-site scripting vulnerability that allows attackers to inject malicious HTML elements into emails by embedding base64-encoded payloads in object and embed tags. Attackers can…
CVE-2026-2493Alta (7.5)3.9%—16 mar 2026
IceWarp collaboration Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of IceWarp. Authentication is not…
CVE-2025-14500Crítica (9.8)1.5%—23 dic 2025
IceWarp14 X-File-Operation Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of IceWarp. Authentication is not required…
CVE-2025-14499Alta (8.8)0.87%—23 dic 2025
IceWarp gmaps Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of IceWarp. User interaction is required to exploit…
CVE-2024-55218Media (6.1)0.70%—7 ene 2025
IceWarp Server 10.2.1 is vulnerable to Cross Site Scripting (XSS) via the meta parameter.
CVE-2024-0246Media (6.1)0.39%—5 ene 2024
A vulnerability classified as problematic has been found in IceWarp 12.0.2.1/12.0.3.1. This affects an unknown part of the file /install/ of the component Utility Download Handler. The manipulation of the argument lang…
CVE-2023-41013Media (6.1)0.60%—12 sept 2023
Cross Site Scripting (XSS) in Webmail Calendar in IceWarp 10.3.1 allows remote attackers to inject arbitrary web script or HTML via the "p4" field.
CVE-2023-39600Media (6.1)1.2%—25 ago 2023
IceWarp 11.4.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the color parameter.
CVE-2023-37728Media (6.1)1.2%—20 jul 2023
IceWarp v10.2.1 was discovered to contain cross-site scripting (XSS) vulnerability via the color parameter.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application2
  2. T1005 Data from Local System1
  3. T1059 Command and Scripting Interpreter1
  4. T1078 Valid Accounts1
  5. T1189 Drive-by Compromise1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Icewarp