VYPR

Roundcubemail

Sign in to watch

by Roundcube

Source repositories

CVEs (5)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2026-26079Med0.314.70.00Feb 11, 2026Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13 allows Cascading Style Sheets (CSS) injection, e.g., because comments are mishandled.
CVE-2026-25916Med0.284.30.00Feb 9, 2026Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13, when "Block remote images" is used, does not block SVG feImage.
CVE-2023-56310.190.84KEVOct 18, 2023Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a crafted SVG document because of program/lib/Roundcube/rcube_washtml.php behavior. This could allow a remote attacker to load arbitrary JavaScript code.
CVE-2025-684610.120.05KEVDec 18, 2025Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document.
CVE-2025-684600.000.00Dec 18, 2025Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a information disclosure vulnerability in the HTML style sanitizer.