CVE-2025-40632
Severity CVSS v4.0:
LOW
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
16/05/2025
Last modified:
09/10/2025
Description
Cross-site scripting (XSS) in Icewarp Mail Server affecting version 11.4.0. This vulnerability allows an attacker to modify the “lastLogin” cookie with malicious JavaScript code that will be executed when the page is rendered.
Impact
Base Score 4.0
2.00
Severity 4.0
LOW
Base Score 3.x
6.10
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:icewarp:mail_server:11.4.0:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



