Skip to main content

Vendor/product archive

roundcube / webmail CVEs

Beta · best-effort

85 CVEs tagged to roundcube / webmail8 Critical, 17 High, 53 Medium, 7 Low, 0 Unrated.

CVE-2026-54433

Published Jul 14, 2026

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafted plain-text email message. The attacker-controlled JavaScript ex…

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-62644

Published Jul 14, 2026

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing via session data, which could lead to acco…

CVSS 6.4 · Medium
evidence mentions
7
Buzz score
30.8
Vendor/product tagsBeta · best-effort

CVE-2026-62643

Published Jul 14, 2026

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosur…

CVSS 7.2 · High
evidence mentions
5
Buzz score
27.9
Vendor/product tagsBeta · best-effort

CVE-2026-62642

Published Jul 14, 2026

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, an infinite loop was discovered in the TNEF decoder, which may lead to denial of service upon opening an email with a TN…

CVSS 4.3 · Medium
evidence mentions
7
Buzz score
30.8
Vendor/product tagsBeta · best-effort

CVE-2026-62641

Published Jul 14, 2026

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the TNEF decoder was subject to denial of service via a crafted compressed-RTF size.

CVSS 4.3 · Medium
evidence mentions
5
Buzz score
27.9
Vendor/product tagsBeta · best-effort

CVE-2026-35545

Published Apr 3, 2026

An issue was discovered in Roundcube Webmail before 1.5.15 and 1.6.15. The remote image blocking feature can be bypassed via SVG content in an e-mail message. This may lead to inf…

CVSS 5.3 · Medium
evidence mentions
7
Buzz score
30.8
Vendor/product tagsBeta · best-effort

CVE-2026-35544

Published Apr 3, 2026

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to a fixed-position…

CVSS 5.3 · Medium
evidence mentions
7
Buzz score
30.8
Vendor/product tagsBeta · best-effort

CVE-2026-35543

Published Apr 3, 2026

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via SVG content (with animate attributes) in an e-mail mes…

CVSS 5.3 · Medium
evidence mentions
7
Buzz score
30.8
Vendor/product tagsBeta · best-effort

CVE-2026-35542

Published Apr 3, 2026

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via a crafted background attribute of a BODY element in an…

CVSS 5.3 · Medium
evidence mentions
7
Buzz score
30.8
Vendor/product tagsBeta · best-effort

CVE-2026-35541

Published Apr 3, 2026

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Incorrect password comparison in the password plugin could lead to type confusion that allows a password cha…

CVSS 4.2 · Medium
evidence mentions
7
Buzz score
30.8
Vendor/product tagsBeta · best-effort

CVE-2026-35540

Published Apr 3, 2026

An issue was discovered in Roundcube Webmail 1.6.0 before 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Di…

CVSS 5.4 · Medium
evidence mentions
5
Buzz score
27.9
Vendor/product tagsBeta · best-effort

CVE-2026-35539

Published Apr 3, 2026

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. XSS exists because of insufficient HTML attachment sanitization in preview mode. A victim must preview a tex…

CVSS 6.1 · Medium
evidence mentions
7
Buzz score
30.8
Vendor/product tagsBeta · best-effort

CVE-2026-35538

Published Apr 3, 2026

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsanitized IMAP SEARCH command arguments could lead to IMAP injection or CSRF bypass during mail search.

CVSS 3.1 · Low
evidence mentions
7
Buzz score
30.8
Vendor/product tagsBeta · best-effort

CVE-2026-35537

Published Apr 3, 2026

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsafe deserialization in the redis/memcache session handler may lead to arbitrary file write operations by…

CVSS 3.7 · Low
evidence mentions
8
Buzz score
33.5
Vendor/product tagsBeta · best-effort

CVE-2025-68461

Published Dec 18, 2025

Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document.

CVSS 7.2 · High
evidence mentions
4
Buzz score
54.1
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2025-68460

Published Dec 18, 2025

Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a information disclosure vulnerability in the HTML style sanitizer.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2025-49113

Published Jun 2, 2025

Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/action…

CVSS 9.9 · Critical
evidence mentions
13
Buzz score
68.9
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2024-57004

Published Feb 3, 2025

Cross-Site Scripting (XSS) vulnerability in Roundcube Webmail 1.6.9 allows remote authenticated users to upload a malicious file as an email attachment, leading to the triggering…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-42009

Published Aug 5, 2024

A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a crafted e-mail message…

CVSS 9.3 · Critical
evidence mentions
11
Buzz score
63.9
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2024-42008

Published Aug 5, 2024

A Cross-Site Scripting vulnerability in rcmail_action_mail_get->run() in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a vic…

CVSS 9.3 · Critical
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2024-37385

Published Jun 7, 2024

Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 on Windows allows command injection via im_convert_path and im_identify_path. NOTE: this issue exists because of an incomplet…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-25 of 85 CVEsPage 1 of 4