References https://nvd.nist.gov/vuln/detail/CVE-2025-40630 https://github.com/advisories/GHSA-hf55-g8pm-mm27 https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-icewarp-mail-server https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-40630.yaml https://cve.akaoma.com/cve-2025-40630 https://cert.kenet.or.ke/cve-2025-40630-icewarp-mail-server-open-redirection-vulnerability https://s4e.io/tools/icewarp-mail-server-open-redirect-cve-2025-40630 https://cve.imfht.com/detail/CVE-2025-40630?lang=en
Related VulnerabilitiesCuteHttpFileServer/chfs存在未授权任意文件上传PoCCVE-2026-2113: tpadmin <= 1.3.12 - Remote Code ExecutionPoCCVE-2026-28411: WeGIA < 3.6.5 - Unauthenticated Authentication Bypass via extract()PoCCVE-2026-56292: AcyMailing < 10.11.1 - Unauthenticated SQL InjectionPoCCVE-2026-62382: PasswordPusher v1.45.11-v2.9.5 - Unauthenticated Anonymous Push Deletion via Ownership BypassPoCCVE-2026-81199: MasterStudy LMS < 3.7.46 - Unauthenticated Student Statistics Disclosure北京亿赛通科技发展有限责任公司电子文档安全管理系统CDGServer3-client存在前台sql漏洞PoCCVE-2026-42596: Gotenberg < 8.31.0 - Server-Side Request ForgeryPoCCVE-2025-53887: Directus < 11.9.0 - Version DisclosurePoCCVE-2026-11387: SMS Alert – SMS & OTP for WooCommerce - Privilege EscalationPoCCVE-2026-11801: WPAdverts <= 2.3.2 - Information DisclosurePoCCVE-2026-45695: Kopia Server 0.23.0 - Remote Code ExecutionPoCCVE-2026-61511: vBulletin 6.x - Remote Code Execution