CVE detail
CVE-2024-42009
A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a crafted e-mail message that abuses a Desanitization issue in message_body() in program/actions/mail/show.php.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 24.9 · diversity 14.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 4
- within the 30d window
- Peak daily
- 2
- highest bucket
Evidence
Source links by recency
11 source links · newest first
- Suspected Chinese snoops caught breaking into universities' Roundcube mailserversThe Register Security
s and, as such, are frequently targeted by government-backed cyber goons. To gain initial access, the intruders exploit CVE-2024-42009, a cross-site scripting vulnerability in Roundcube that only requires that the email is opened in the mail client to achieve access to the server. “The targeted departments were likely specifically chosen because they w
newswww.theregister.comJul 8, 2026, 9:35 PM - Hackers exploit Roundcube flaw to spy on academic researchersBleepingComputer
ning the email in a vulnerable Roundcube webmail client triggers exploitation of a cross-site scripting flaw tracked as CVE-2024-42009, which executes JavaScript code inside the victim’s browser, loading a payload called IceCube. According to the researchers, IceCube "is a fully-featured Roundcube stealer" that can harvest usernames, passwords, cookies
newswww.bleepingcomputer.comJul 8, 2026, 6:56 PM - Suspected Chinese Threat Group Targets Universities via Vulnerable Roundcube ServersInfosecurity Magazine
try Points Proofpoint found that UNK_MassTraction used phishing emails containing malicious content designed to exploit CVE-2024-42009, a cross-site scripting (XSS) vulnerability in Roundcube. When executed in a vulnerable webmail client, the exploit allowed JavaScript to run in the victim's browser. The JavaScript payload, tracked by Proofpoint as Ice
newswww.infosecurity-magazine.comJul 7, 2026, 3:40 PM e activity involves the exploitation of now-patched, critical security flaws in the open-source email solution, such as CVE-2024-42009 (CVSS score: 9.3), to siphon credentials,
newsthehackernews.comJul 7, 2026, 9:10 AMState-aligned hacking groups have spent the past six months ramping up espionage, sabotage, and cybercrime campaigns across multiple regions, according to ESET’s APT Activity Report covering April through September 2025. The research highlights how operations linked to Russia, China, Iran, and North Korea have evolved in scope and technique, showing that nation-state activity remains a constant source of disruption. Attack sources (Source: ESET) Russia’s focus on Ukraine and its allies Russia-linked actors remained among the … More →
newswww.helpnetsecurity.comNov 6, 2025, 10:00 AM- U.S. CISA adds RoundCube Webmail and Erlang Erlang/OTP SSH server flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds RoundCube Webmail and Erlang Erlang/OTP SSH server flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added RoundCube Webmail and Erlang Erlang/OTP SSH server flaws to its Known Exploited Vulnerabilities (KEV) catalog. Below are the descriptions for these flaws: The CVE-2025-32433 flaw is a […]
newssecurityaffairs.comJun 10, 2025, 1:34 PM Exploitation of a critical-severity RCE vulnerability in Roundcube started only days after a patch was released.
newswww.securityweek.comJun 10, 2025, 9:38 AMWith an exploit for a critical Roundcube vulnerability (CVE-2025-49113) being offered for sale on underground forums and a PoC exploit having been made public, attacks exploiting the flaw are incoming and possibly already happening. According to the Shadowserver Foundation, there is no lack of possible targets: around 84,000 internet-facing installations – predominantly in Europe, Asia, and North America – are still unpatched. What is Roundcube? Roundcube is a free and open-source web-based email client that’s … More →
newswww.helpnetsecurity.comJun 9, 2025, 12:06 PM- Week in review: Tips for starting your cybersecurity career, Patch Tuesday forecastHelp Net Security
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: August 2024 Patch Tuesday forecast: Looking for a calm August release August 2024 July ended up being more ‘exciting’ than many of us wanted; we’re supposed to be in the height of summer vacation season. First, we had a large set of updates on Patch Tuesday, then we had to work through the CrowdStrike event, and finally many of us … More →
newswww.helpnetsecurity.comAug 11, 2024, 8:00 AM - Critical XSS bug in Roundcube Webmail allows attackers to steal emails and sensitive dataSecurity Affairs
Researchers warn of flaws in the Roundcube webmail software that could be exploited to steal sensitive information from target accounts. Sonar’s Vulnerability Research Team discovered a critical Cross-Site Scripting (XSS) vulnerability in the popular open-source webmail software Roundcube. Roundcube is included by default in the server hosting panel cPanel which has millions of installations worldwide. […]
newssecurityaffairs.comAug 7, 2024, 9:10 PM - Roundcube flaws allow easy email account compromise (CVE-2024-42009, CVE-2024-42008)Help Net Security
Two cross-site scripting vulnerabilities (CVE-2024-42009, CVE-2024-42008) affecting Roundcube could be exploited by attackers to steal users’ emails and contacts, email password, and send emails from their account. About the vulnerabilities Roundcube is an open-source webmail software solution popular with European government agencies, hosting providers and academic institutions around the world. CVE-2024-42009 and CVE-2024-42008 are both XSS bugs. The former allows a remote attacker to steal and send emails of a victim via a crafted e-mail … More →
newswww.helpnetsecurity.comAug 7, 2024, 8:59 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-54433CVSS 7.2 · High
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafted plain-text email message. The attacker-controlled JavaScript ex…
- CVE-2026-35539CVSS 6.1 · Medium
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. XSS exists because of insufficient HTML attachment sanitization in preview mode. A victim must preview a tex…
- CVE-2025-68461CVSS 7.2 · High
Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document.
- CVE-2024-42008CVSS 9.3 · Critical
A Cross-Site Scripting vulnerability in rcmail_action_mail_get->run() in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a vic…
- CVE-2024-37384CVSS 6.1 · Medium
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via list columns from user preferences.
- CVE-2024-37383CVSS 6.1 · Medium
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.