VYPR
Vendor

Roundcube

Roundcube is a web-based IMAP email client written in PHP. It uses Ajax throughout its interface and is licensed under the GNU GPL version 3 or later, with exceptions for skins and plugins.

Founded 2008
Products
4
CVEs
115
Across products
203
Status
Private

Products

4

Recent CVEs

115
View all 115 CVEs →
  • CVE-2020-12641CriKEVMay 4, 2020
    risk 0.82cvss 9.8epss 0.84

    rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setting for im_convert_path or im_identify_path.

  • CVE-2021-44026CriKEVNov 19, 2021
    risk 0.81cvss 9.8epss 0.70

    Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.

  • CVE-2025-49113CriKEVJun 2, 2025
    risk 0.80cvss 9.9epss 0.99

    Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP Object Deserialization.

  • CVE-2024-42009CriKEVAug 5, 2024
    risk 0.72cvss 9.3epss 0.83

    A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a crafted e-mail message that abuses a Desanitization issue in message_body() in program/actions/mail/show.php.

  • CVE-2020-12640CriMay 4, 2020
    risk 0.64cvss 9.8epss 0.07

    Roundcube Webmail before 1.4.4 allows attackers to include local files and execute code via directory traversal in a plugin name to rcube_plugin_api.php.

  • CVE-2024-42008CriAug 5, 2024
    risk 0.63cvss 9.3epss 0.34

    A Cross-Site Scripting vulnerability in rcmail_action_mail_get->run() in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a malicious e-mail attachment served with a dangerous Content-Type header.

  • CVE-2017-16651HigKEVNov 9, 2017
    risk 0.62cvss 7.8epss 0.46

    Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's filesystem, including configuration files, as exploited in the wild in November 2017. The attacker must be able to authenticate at the target…

  • CVE-2020-13965MedKEVJun 9, 2020
    risk 0.58cvss 6.1epss 0.77

    An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is among the allowed types for a preview.

  • CVE-2018-9846HigApr 7, 2018
    risk 0.57cvss 8.8epss 0.02

    In Roundcube from versions 1.2.0 to 1.3.5, with the archive plugin enabled and configured, it's possible to exploit the unsanitized, user-controlled "_uid" parameter (in an archive.php _task=mail&_mbox=INBOX&_action=plugin.move2archive request) to perform an MX (IMAP) injection…

  • CVE-2017-8114HigApr 29, 2017
    risk 0.57cvss 8.8epss 0.03

    Roundcube Webmail allows arbitrary password resets by authenticated users. This affects versions before 1.0.11, 1.1.x before 1.1.9, and 1.2.x before 1.2.5. The problem is caused by an improperly restricted exec call in the virtualmin and sasl drivers of the password plugin.

  • CVE-2016-4069HigAug 25, 2016
    risk 0.57cvss 8.8epss 0.03

    Cross-site request forgery (CSRF) vulnerability in Roundcube Webmail before 1.1.5 allows remote attackers to hijack the authentication of users for requests that download attachments and cause a denial of service (disk consumption) via unspecified vectors.

  • CVE-2024-37383MedKEVJun 7, 2024
    risk 0.54cvss 6.1epss 0.73

    Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.

  • CVE-2015-8770HigJan 29, 2016
    risk 0.54cvss 7.5epss 0.22

    Directory traversal vulnerability in the set_skin function in program/include/rcmail_output_html.php in Roundcube before 1.0.8 and 1.1.x before 1.1.4 allows remote authenticated users with certain permissions to read arbitrary files or possibly execute arbitrary code via a ..…

  • CVE-2015-2180HigJan 30, 2017
    risk 0.51cvss 8.8epss 0.05

    The DBMail driver in the Password plugin in Roundcube before 1.1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the password.

  • CVE-2026-74997HigAug 17, 2026
    risk 0.50cvss 8.8epss 0.01

    In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the cmd_learn driver of the markasjunk plugin is subject to remote code execution via crafted placeholder replacement values. This issue only affects Roundcube instances using the markasjunk plugin with its cmd_learn…

  • CVE-2015-2181HigJan 30, 2017
    risk 0.50cvss 8.8epss 0.03

    Multiple buffer overflows in the DBMail driver in the Password plugin in Roundcube before 1.1.0 allow remote attackers to have unspecified impact via the (1) password or (2) username.

  • CVE-2023-3222HigSep 4, 2023
    risk 0.49cvss 7.5epss 0.01

    Vulnerability in the password recovery mechanism of Password Recovery plugin for Roundcube, in its 1.2 version, which could allow a remote attacker to change an existing user´s password by adding a 6-digit numeric token. An attacker could create an automatic script to test all…

  • CVE-2018-19205HigNov 12, 2018
    risk 0.49cvss 7.5epss 0.02

    Roundcube before 1.3.7 mishandles GnuPG MDC integrity-protection warnings, which makes it easier for attackers to obtain sensitive information, a related issue to CVE-2017-17688. This is associated with plugins/enigma/lib/enigma_driver_gnupg.php.

  • CVE-2018-1000072HigMar 13, 2018
    risk 0.49cvss 7.5epss 0.02

    iRedMail version prior to commit f04b8ef contains a Insecure Permissions vulnerability in Roundcube Webmail that can result in Exfiltrate a user's password protected secret GPG key file and other important configuration files.. This attack appear to be exploitable via network…

  • CVE-2018-1000071HigMar 13, 2018
    risk 0.49cvss 7.5epss 0.02

    roundcube version 1.3.4 and earlier contains an Insecure Permissions vulnerability in enigma plugin that can result in exfiltration of gpg private key. This attack appear to be exploitable via network connectivity.