Skip to main content

CVE detail

CVE-2025-49113

Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP Object Deserialization.

CVSS 9.9 · CriticalBuzz score 68.9KEV listed

Buzz score

Why this CVE is surfacing

Buzz score total 68.9

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 26.4 · diversity 17.5 · KEV 25.0 · OTX 0.0 · PoC 0.0
Mention score
26.4
13 evidence mentions in the snapshot
Diversity score
17.5
7 sources across 2 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
3
within the 30d window
Peak daily
2
highest bucket

Evidence

Source links by recency

Newest mentions first
13 source links · newest first
  • s and, as such, are frequently targeted by government-backed cyber goons. To gain initial access, the intruders exploit CVE-2024-42009, a cross-site scripting vulnerability in Roundcube that only requires that the email is opened in the mail client to achieve access to the server. “The targeted departments were likely specifically chosen because they w

    newswww.theregister.comJul 8, 2026, 9:35 PM
  • ning the email in a vulnerable Roundcube webmail client triggers exploitation of a cross-site scripting flaw tracked as CVE-2024-42009, which executes JavaScript code inside the victim’s browser, loading a payload called IceCube. According to the researchers, IceCube "is a fully-featured Roundcube stealer" that can harvest usernames, passwords, cookies

    newswww.bleepingcomputer.comJul 8, 2026, 6:56 PM
  • try Points Proofpoint found that UNK_MassTraction used phishing emails containing malicious content designed to exploit CVE-2024-42009, a cross-site scripting (XSS) vulnerability in Roundcube. When executed in a vulnerable webmail client, the exploit allowed JavaScript to run in the victim's browser. The JavaScript payload, tracked by Proofpoint as Ice

    newswww.infosecurity-magazine.comJul 7, 2026, 3:40 PM
  • 2nd March – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 2nd March, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Wynn Resorts, a United States-based casino and hotel operator, has confirmed that employee data was accessed following an extortion threat linked to ShinyHunters. The company said operations were not disrupted. Reports indicate […]

    vendorresearch.checkpoint.comMar 2, 2026, 4:29 PM
  • Patched in December 2025, the exploited flaw leads to XSS attacks via the animate tags in SVG documents.

    newswww.securityweek.comFeb 23, 2026, 10:47 AM
  • U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds RoundCube Webmail flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added two RoundCube Webmail flaws to its Known Exploited Vulnerabilities (KEV) catalog. Below are the flaws added to the catalog: Roundcube is a popular webmail platform and has been repeatedly targeted […]

    newssecurityaffairs.comFeb 21, 2026, 11:19 AM
  • Russia-linked actors use AI to craft phishing and malware attacks against entities in Ukraine, says SSSCIP. Russian hackers increasingly use AI in cyberattacks against Ukraine, the country’s State Service for Special Communications and Information Protection (SSSCIP) reported. Beyond AI-generated phishing, some malware samples now show AI-generated code. In H1 2025, Ukraine recorded 3,018 cyber incidents, […]

    newssecurityaffairs.comOct 10, 2025, 1:31 PM
  • Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Microsoft fixes zero-day exploited for cyber espionage (CVE-2025-33053) For June 2025 Patch Tuesday, Microsoft has fixed 66 new CVEs, including a zero-day exploited in the wild (CVE-2025-33053). Unpatched Wazuh servers targeted by Mirai botnets (CVE-2025-24016) Two Mirai botnets are exploiting a critical remote code execution vulnerability (CVE-2025-24016) in the open-source Wazuh XDR/SIEM platform, Akamai researchers have warned. Want fewer security … More →

    newswww.helpnetsecurity.comJun 15, 2025, 8:00 AM
  • A critical remote code execution (RCE) vulnerability in Roundcube was exploited days after patch, impacting over 80,000 servers. Threat actors exploited a critical remote code execution (RCE) flaw in Roundcube, tracked as CVE-2025-49113, just days after the patch was released, targeting over 80,000 servers. Roundcube is a popular webmail platform and has been repeatedly targeted […]

    newssecurityaffairs.comJun 11, 2025, 11:39 AM
  • Exploitation of a critical-severity RCE vulnerability in Roundcube started only days after a patch was released.

    newswww.securityweek.comJun 10, 2025, 9:38 AM
  • With an exploit for a critical Roundcube vulnerability (CVE-2025-49113) being offered for sale on underground forums and a PoC exploit having been made public, attacks exploiting the flaw are incoming and possibly already happening. According to the Shadowserver Foundation, there is no lack of possible targets: around 84,000 internet-facing installations – predominantly in Europe, Asia, and North America – are still unpatched. What is Roundcube? Roundcube is a free and open-source web-based email client that’s … More →

    newswww.helpnetsecurity.comJun 9, 2025, 12:06 PM
  • 9th June – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 9th June, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES American tax company, Optima Tax Relief, has disclosed a ransomware attack that resulted in the theft of 69GB of sensitive data, including corporate records and customer case files containing personal information such […]

    vendorresearch.checkpoint.comJun 9, 2025, 8:55 AM
  • A critical flaw in Roundcube webmail, undetected for 10 years, allows attackers to take over systems and execute arbitrary code. A critical flaw, tracked as CVE-2025-49113 (CVSS score of 9.9) has been discovered in the Roundcube webmail software. The vulnerability went unnoticed for over a decade, an attacker can exploit the flaw to take control […]

    newssecurityaffairs.comJun 4, 2025, 11:35 AM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence