Vulnerability index

Browse CVEs

47 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Webmail CRITICAL 10.0
CVE-2026-54433

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafted plain-text email message. The att…

Fix: 1.6.17 / 1.7.2+
Fix from $2,300 2026-07-14
Webmail CRITICAL 10.0
CVE-2026-62643

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to…

Fix: 1.6.17 / 1.7.2+
Fix from $2,300 2026-07-14
Webmail CRITICAL 9.8
CVE-2026-62644

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing via session …

Fix: 1.6.17 / 1.7.2+
Fix from $2,300 2026-07-14
Webmail MEDIUM 6.5
CVE-2026-62641

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the TNEF decoder was subject to denial of service via a crafted compressed-RTF size.

Fix: 1.6.17 / 1.7.2+
Fix from $1,600 2026-07-14
Webmail MEDIUM 6.5
CVE-2026-62642

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, an infinite loop was discovered in the TNEF decoder, which may lead to denial of service u…

Fix: 1.6.17 / 1.7.2+
Fix from $1,600 2026-07-14
Webmail HIGH 8.2
CVE-2026-35545

An issue was discovered in Roundcube Webmail before 1.5.15 and 1.6.15. The remote image blocking feature can be bypassed via SVG content in an e-mail…

Fix: 1.5.15 / 1.6.15+
Fix from $1,950 2026-04-03
Webmail MEDIUM 6.5
CVE-2026-35540

An issue was discovered in Roundcube Webmail 1.6.0 before 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may …

Fix: 1.6.14+
Fix from $1,600 2026-04-03
Webmail MEDIUM 5.3
CVE-2026-35542

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via a crafted background att…

Fix: 1.5.14 / 1.6.14+
Fix from $1,600 2026-04-03
Webmail MEDIUM 5.3
CVE-2026-35543

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via SVG content (with animat…

Fix: 1.5.14 / 1.6.14+
Fix from $1,600 2026-04-03
Webmail MEDIUM 5.3
CVE-2026-35544

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages…

Fix: after 1.6.13
Fix from $1,600 2026-04-03
Webmail MEDIUM 6.1
CVE-2026-35539

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. XSS exists because of insufficient HTML attachment sanitization in preview mod…

Fix: 1.5.14 / 1.6.14+
Fix from $1,600 2026-04-03
Webmail HIGH 7.5
CVE-2026-35537

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsafe deserialization in the redis/memcache session handler may lead to arbit…

Fix: 1.5.14 / 1.6.14+
Fix from $1,950 2026-04-03
Webmail MEDIUM 6.1
CVE-2025-68461 KEVEPSS 21%

Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document.

Fix: 1.5.12 / 1.6.12+
Fix from $1,600 2025-12-18
Webmail HIGH 7.5
CVE-2025-68460

Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a information disclosure vulnerability in the HTML style sanitizer.

Fix: 1.5.12 / 1.6.12+
Fix from $1,950 2025-12-18
Webmail MEDIUM 6.1
CVE-2024-57004EPSS 29%

Cross-Site Scripting (XSS) vulnerability in Roundcube Webmail 1.6.9 allows remote authenticated users to upload a malicious file as an email attachme…

No fix yet
Fix from $1,600 2025-02-03
Webmail CRITICAL 9.3
CVE-2024-42008EPSS 36%

A Cross-Site Scripting vulnerability in rcmail_action_mail_get->run() in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to …

Fix: 1.5.8 / 1.6.8+
Fix from $2,300 2024-08-05
Webmail CRITICAL 9.3
CVE-2024-42009 KEVEPSS 80%

A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim…

Fix: 1.5.8 / 1.6.8+
Fix from $2,300 2024-08-05
Webmail CRITICAL 9.8
CVE-2024-37385

Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 on Windows allows command injection via im_convert_path and im_identify_path. NOTE: this issue …

Fix: 1.5.7 / 1.6.7+
Fix from $2,300 2024-06-07
Webmail MEDIUM 5.4
CVE-2020-18670

Cross Site Scripting (XSS) vulneraibility in Roundcube mail .4.4 via database host and user in /installer/test.php.

Patch available
Fix from $1,600 2021-06-24
Webmail MEDIUM 5.4
CVE-2020-18671

Cross Site Scripting (XSS) vulnerability in Roundcube Mail <=1.4.4 via smtp config in /installer/test.php.

Fix: after 1.4.4
Fix from $1,600 2021-06-24
Webmail CRITICAL 9.8
CVE-2020-12640EPSS 7%

Roundcube Webmail before 1.4.4 allows attackers to include local files and execute code via directory traversal in a plugin name to rcube_plugin_api.…

Fix: 1.2.10 / 1.3.11+
Fix from $2,300 2020-05-04
Webmail CRITICAL 9.8
CVE-2020-12641 KEVEPSS 84%

rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setting for …

Fix: 1.2.10 / 1.3.11+
Fix from $2,300 2020-05-04
Webmail HIGH 7.5
CVE-2018-19205

Roundcube before 1.3.7 mishandles GnuPG MDC integrity-protection warnings, which makes it easier for attackers to obtain sensitive information, a rel…

Fix: 1.3.7+
Fix from $1,950 2018-11-12
Webmail HIGH 7.5
CVE-2018-1000071

roundcube version 1.3.4 and earlier contains an Insecure Permissions vulnerability in enigma plugin that can result in exfiltration of gpg private ke…

Fix: after 1.3.4
Fix from $1,950 2018-03-13
Roundcube Webmail HIGH 7.5
CVE-2015-5383

Roundcube Webmail 1.1.x before 1.1.2 allows remote attackers to obtain sensitive information by reading files in the (1) config, (2) temp, or (3) log…

Patch available
Fix from $1,950 2017-05-23
Roundcube Webmail MEDIUM 6.5
CVE-2015-5382

program/steps/addressbook/photo.inc in Roundcube Webmail before 1.0.6 and 1.1.x before 1.1.2 allows remote authenticated users to read arbitrary file…

Fix: after 1.0.5
Fix from $1,600 2017-05-23
Roundcube Webmail MEDIUM 6.1
CVE-2015-5381

Cross-site scripting (XSS) vulnerability in program/include/rcmail.php in Roundcube Webmail 1.1.x before 1.1.2 allows remote attackers to inject arbi…

Patch available
Fix from $1,600 2017-05-23
Webmail HIGH 8.8
CVE-2017-8114

Roundcube Webmail allows arbitrary password resets by authenticated users. This affects versions before 1.0.11, 1.1.x before 1.1.9, and 1.2.x before …

Fix: 1.0.11 / 1.1.9+
Fix from $1,950 2017-04-29
Webmail MEDIUM 6.1
CVE-2017-6820

rcube_utils.php in Roundcube before 1.1.8 and 1.2.x before 1.2.4 is susceptible to a cross-site scripting vulnerability via a crafted Cascading Style…

Fix: after 1.1.7
Fix from $1,600 2017-03-12
Webmail HIGH 8.8
CVE-2015-2180

The DBMail driver in the Password plugin in Roundcube before 1.1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in …

Fix: after 1.1
Fix from $1,950 2017-01-30