Vulnerability index

Browse CVEs

47 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 10.0 CVE-2026-54433 In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafted plain-text email message. The att… Webmail 1.6.17 / 1.7.2+ Fix from $2,3002026-07-14 CRITICAL 10.0 CVE-2026-62643 In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to… Webmail 1.6.17 / 1.7.2+ Fix from $2,3002026-07-14 CRITICAL 9.8 CVE-2026-62644 In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing via session … Webmail 1.6.17 / 1.7.2+ Fix from $2,3002026-07-14 MEDIUM 6.5 CVE-2026-62641 In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the TNEF decoder was subject to denial of service via a crafted compressed-RTF size. Webmail 1.6.17 / 1.7.2+ Fix from $1,6002026-07-14 MEDIUM 6.5 CVE-2026-62642 In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, an infinite loop was discovered in the TNEF decoder, which may lead to denial of service u… Webmail 1.6.17 / 1.7.2+ Fix from $1,6002026-07-14 HIGH 8.2 CVE-2026-35545 An issue was discovered in Roundcube Webmail before 1.5.15 and 1.6.15. The remote image blocking feature can be bypassed via SVG content in an e-mail… Webmail 1.5.15 / 1.6.15+ Fix from $1,9502026-04-03 MEDIUM 6.5 CVE-2026-35540 An issue was discovered in Roundcube Webmail 1.6.0 before 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may … Webmail 1.6.14+ Fix from $1,6002026-04-03 MEDIUM 5.3 CVE-2026-35542 An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via a crafted background att… Webmail 1.5.14 / 1.6.14+ Fix from $1,6002026-04-03 MEDIUM 5.3 CVE-2026-35543 An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via SVG content (with animat… Webmail 1.5.14 / 1.6.14+ Fix from $1,6002026-04-03 MEDIUM 5.3 CVE-2026-35544 An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages… Webmail after 1.6.13 Fix from $1,6002026-04-03 MEDIUM 6.1 CVE-2026-35539 An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. XSS exists because of insufficient HTML attachment sanitization in preview mod… Webmail 1.5.14 / 1.6.14+ Fix from $1,6002026-04-03 HIGH 7.5 CVE-2026-35537 An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsafe deserialization in the redis/memcache session handler may lead to arbit… Webmail 1.5.14 / 1.6.14+ Fix from $1,9502026-04-03 MEDIUM 6.1 CVE-2025-68461 KEVEPSS 21% Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document. Webmail 1.5.12 / 1.6.12+ Fix from $1,6002025-12-18 HIGH 7.5 CVE-2025-68460 Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a information disclosure vulnerability in the HTML style sanitizer. Webmail 1.5.12 / 1.6.12+ Fix from $1,9502025-12-18 MEDIUM 6.1 CVE-2024-57004EPSS 29% Cross-Site Scripting (XSS) vulnerability in Roundcube Webmail 1.6.9 allows remote authenticated users to upload a malicious file as an email attachme… Webmail No fix yet Fix from $1,6002025-02-03 CRITICAL 9.3 CVE-2024-42008EPSS 36% A Cross-Site Scripting vulnerability in rcmail_action_mail_get->run() in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to … Webmail 1.5.8 / 1.6.8+ Fix from $2,3002024-08-05 CRITICAL 9.3 CVE-2024-42009 KEVEPSS 80% A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim… Webmail 1.5.8 / 1.6.8+ Fix from $2,3002024-08-05 CRITICAL 9.8 CVE-2024-37385 Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 on Windows allows command injection via im_convert_path and im_identify_path. NOTE: this issue … Webmail 1.5.7 / 1.6.7+ Fix from $2,3002024-06-07 MEDIUM 5.4 CVE-2020-18670 Cross Site Scripting (XSS) vulneraibility in Roundcube mail .4.4 via database host and user in /installer/test.php. Webmail Patch available Fix from $1,6002021-06-24 MEDIUM 5.4 CVE-2020-18671 Cross Site Scripting (XSS) vulnerability in Roundcube Mail <=1.4.4 via smtp config in /installer/test.php. Webmail after 1.4.4 Fix from $1,6002021-06-24 CRITICAL 9.8 CVE-2020-12640EPSS 7% Roundcube Webmail before 1.4.4 allows attackers to include local files and execute code via directory traversal in a plugin name to rcube_plugin_api.… Webmail 1.2.10 / 1.3.11+ Fix from $2,3002020-05-04 CRITICAL 9.8 CVE-2020-12641 KEVEPSS 84% rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setting for … Webmail 1.2.10 / 1.3.11+ Fix from $2,3002020-05-04 HIGH 7.5 CVE-2018-19205 Roundcube before 1.3.7 mishandles GnuPG MDC integrity-protection warnings, which makes it easier for attackers to obtain sensitive information, a rel… Webmail 1.3.7+ Fix from $1,9502018-11-12 HIGH 7.5 CVE-2018-1000071 roundcube version 1.3.4 and earlier contains an Insecure Permissions vulnerability in enigma plugin that can result in exfiltration of gpg private ke… Webmail after 1.3.4 Fix from $1,9502018-03-13 HIGH 7.5 CVE-2015-5383 Roundcube Webmail 1.1.x before 1.1.2 allows remote attackers to obtain sensitive information by reading files in the (1) config, (2) temp, or (3) log… Roundcube Webmail Patch available Fix from $1,9502017-05-23 MEDIUM 6.5 CVE-2015-5382 program/steps/addressbook/photo.inc in Roundcube Webmail before 1.0.6 and 1.1.x before 1.1.2 allows remote authenticated users to read arbitrary file… Roundcube Webmail after 1.0.5 Fix from $1,6002017-05-23 MEDIUM 6.1 CVE-2015-5381 Cross-site scripting (XSS) vulnerability in program/include/rcmail.php in Roundcube Webmail 1.1.x before 1.1.2 allows remote attackers to inject arbi… Roundcube Webmail Patch available Fix from $1,6002017-05-23 HIGH 8.8 CVE-2017-8114 Roundcube Webmail allows arbitrary password resets by authenticated users. This affects versions before 1.0.11, 1.1.x before 1.1.9, and 1.2.x before … Webmail 1.0.11 / 1.1.9+ Fix from $1,9502017-04-29 MEDIUM 6.1 CVE-2017-6820 rcube_utils.php in Roundcube before 1.1.8 and 1.2.x before 1.2.4 is susceptible to a cross-site scripting vulnerability via a crafted Cascading Style… Webmail after 1.1.7 Fix from $1,6002017-03-12 HIGH 8.8 CVE-2015-2180 The DBMail driver in the Password plugin in Roundcube before 1.1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in … Webmail after 1.1 Fix from $1,9502017-01-30