VYPR

Vendor CVEs

Roundcube

All CVEs

99 total · sorted by risk
  • CVE-2020-35730KEVDec 28, 2020
    risk 0.10cvss epss 0.33

    An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attacker can send a plain text e-mail message, with JavaScript in a link reference element that is mishandled by linkref_addindex in rcube_string_replacer.php.

  • CVE-2024-42008Aug 5, 2024
    risk 0.04cvss epss 0.32

    A Cross-Site Scripting vulnerability in rcmail_action_mail_get->run() in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a malicious e-mail attachment served with a dangerous Content-Type header.

  • CVE-2020-12640May 4, 2020
    risk 0.01cvss epss 0.07

    Roundcube Webmail before 1.4.4 allows attackers to include local files and execute code via directory traversal in a plugin name to rcube_plugin_api.php.

  • CVE-2026-9818May 28, 2026
    risk 0.00cvss epss

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2025-68460Dec 18, 2025
    risk 0.00cvss epss 0.00

    Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a information disclosure vulnerability in the HTML style sanitizer.

  • CVE-2024-57004Feb 3, 2025
    risk 0.00cvss epss 0.28

    Cross-Site Scripting (XSS) vulnerability in Roundcube Webmail 1.6.9 allows remote authenticated users to upload a malicious file as an email attachment, leading to the triggering of the XSS by visiting the SENT session.

  • CVE-2024-37385Jun 7, 2024
    risk 0.00cvss epss 0.01

    Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 on Windows allows command injection via im_convert_path and im_identify_path. NOTE: this issue exists because of an incomplete fix for CVE-2020-12641.

  • CVE-2024-37384Jun 7, 2024
    risk 0.00cvss epss 0.01

    Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via list columns from user preferences.

  • CVE-2023-47272Nov 5, 2023
    risk 0.00cvss epss 0.01

    Roundcube 1.5.x before 1.5.6 and 1.6.x before 1.6.5 allows XSS via a Content-Type or Content-Disposition header (used for attachment preview or download).

  • CVE-2023-3222Sep 4, 2023
    risk 0.00cvss epss 0.01

    Vulnerability in the password recovery mechanism of Password Recovery plugin for Roundcube, in its 1.2 version, which could allow a remote attacker to change an existing user´s password by adding a 6-digit numeric token. An attacker could create an automatic script to test all…

  • CVE-2023-3221Sep 4, 2023
    risk 0.00cvss epss 0.00

    User enumeration vulnerability in Password Recovery plugin 1.2 version for Roundcube, which could allow a remote attacker to create a test script against the password recovery function to enumerate all users in the database.

  • CVE-2021-46144Jan 6, 2022
    risk 0.00cvss epss 0.01

    Roundcube before 1.4.13 and 1.5.x before 1.5.2 allows XSS via an HTML e-mail message with crafted Cascading Style Sheets (CSS) token sequences.

  • CVE-2021-44025Nov 19, 2021
    risk 0.00cvss epss 0.01

    Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to XSS in handling an attachment's filename extension when displaying a MIME type warning message.

  • CVE-2020-18671Jun 24, 2021
    risk 0.00cvss epss 0.01

    Cross Site Scripting (XSS) vulnerability in Roundcube Mail <=1.4.4 via smtp config in /installer/test.php.

  • CVE-2020-18670Jun 24, 2021
    risk 0.00cvss epss 0.01

    Cross Site Scripting (XSS) vulneraibility in Roundcube mail .4.4 via database host and user in /installer/test.php.

  • CVE-2021-26925Feb 9, 2021
    risk 0.00cvss epss 0.01

    Roundcube before 1.4.11 allows XSS via crafted Cascading Style Sheets (CSS) token sequences during HTML email rendering.

  • CVE-2020-16145Aug 12, 2020
    risk 0.00cvss epss 0.02

    Roundcube Webmail before 1.3.15 and 1.4.8 allows stored XSS in HTML messages during message display via a crafted SVG document. This issue has been fixed in 1.4.8 and 1.3.15.

  • CVE-2020-15562Jul 6, 2020
    risk 0.00cvss epss 0.02

    An issue was discovered in Roundcube Webmail before 1.2.11, 1.3.x before 1.3.14, and 1.4.x before 1.4.7. It allows XSS via a crafted HTML e-mail message, as demonstrated by a JavaScript payload in the xmlns (aka XML namespace) attribute of a HEAD element when an SVG element…

  • CVE-2020-13964Jun 9, 2020
    risk 0.00cvss epss 0.01

    An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. include/rcmail_output_html.php allows XSS via the username template object.

  • CVE-2020-12625May 4, 2020
    risk 0.00cvss epss 0.03

    An issue was discovered in Roundcube Webmail before 1.4.4. There is a cross-site scripting (XSS) vulnerability in rcube_washtml.php because JavaScript code can occur in the CDATA of an HTML message.

  • CVE-2020-12626May 4, 2020
    risk 0.00cvss epss 0.02

    An issue was discovered in Roundcube Webmail before 1.4.4. A CSRF attack can cause an authenticated user to be logged out because POST was not considered.

  • CVE-2019-15237Aug 20, 2019
    risk 0.00cvss epss 0.01

    Roundcube Webmail through 1.3.9 mishandles Punycode xn-- domain names, leading to homograph attacks.

  • CVE-2019-10740Apr 7, 2019
    risk 0.00cvss epss 0.01

    In Roundcube Webmail before 1.3.10, an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub-parts within a crafted multipart email. The encrypted part(s) can further be hidden using HTML/CSS or ASCII newline characters. This modified multipart email can…

  • CVE-2018-19205Nov 12, 2018
    risk 0.00cvss epss 0.02

    Roundcube before 1.3.7 mishandles GnuPG MDC integrity-protection warnings, which makes it easier for attackers to obtain sensitive information, a related issue to CVE-2017-17688. This is associated with plugins/enigma/lib/enigma_driver_gnupg.php.

  • CVE-2018-19206Nov 12, 2018
    risk 0.00cvss epss 0.60

    steps/mail/func.inc in Roundcube before 1.3.8 has XSS via crafted use of , as demonstrated by an onload attribute in a BODY element, within an HTML attachment.

  • CVE-2015-8105Nov 10, 2015
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in program/js/app.js in Roundcube webmail before 1.0.7 and 1.1.x before 1.1.3 allows remote authenticated users to inject arbitrary web script or HTML via the file name in a drag-n-drop file upload.

  • CVE-2015-1433Feb 3, 2015
    risk 0.00cvss epss 0.03

    program/lib/Roundcube/rcube_washtml.php in Roundcube before 1.0.5 does not properly quote strings, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the style attribute in an email.

  • CVE-2014-9587Jan 15, 2015
    risk 0.00cvss epss 0.02

    Multiple cross-site request forgery (CSRF) vulnerabilities in Roundcube Webmail before 1.0.4 allow remote attackers to hijack the authentication of unspecified victims via unknown vectors, related to (1) address book operations or the (2) ACL or (3) Managesieve plugins.

  • CVE-2013-1904Feb 8, 2014
    risk 0.00cvss epss 0.02

    Absolute path traversal vulnerability in steps/mail/sendmail.inc in Roundcube Webmail before 0.7.3 and 0.8.x before 0.8.6 allows remote attackers to read arbitrary files via a full pathname in the _value parameter for the generic_message_footer setting in a save-perf action to…

  • CVE-2013-6172Nov 5, 2013
    risk 0.00cvss epss 0.03

    steps/utils/save_pref.inc in Roundcube webmail before 0.8.7 and 0.9.x before 0.9.5 allows remote attackers to modify configuration settings via the _session parameter, which can be leveraged to read arbitrary files, conduct SQL injection attacks, and execute arbitrary code.

  • CVE-2013-5646Aug 29, 2013
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in Roundcube webmail 1.0-git allows remote authenticated users to inject arbitrary web script or HTML via the Name field of an addressbook group.

  • CVE-2013-5645Aug 29, 2013
    risk 0.00cvss epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in Roundcube webmail before 0.9.3 allow user-assisted remote attackers to inject arbitrary web script or HTML via the body of a message visited in (1) new or (2) draft mode, related to compose.inc; and (3) might allow remote…

  • CVE-2012-6121Feb 24, 2013
    risk 0.00cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 0.8.5 allows remote attackers to inject arbitrary web script or HTML via a (1) data:text or (2) vbscript link.

  • CVE-2012-4668Aug 25, 2012
    risk 0.00cvss epss 0.04

    Cross-site scripting (XSS) vulnerability in Roundcube Webmail 0.8.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the signature in an email.

  • CVE-2012-3508Aug 25, 2012
    risk 0.00cvss epss 0.04

    Cross-site scripting (XSS) vulnerability in program/lib/washtml.php in Roundcube Webmail 0.8.0 allows remote attackers to inject arbitrary web script or HTML by using "javascript:" in an href attribute in the body of an HTML-formatted email.

  • CVE-2012-3507Aug 25, 2012
    risk 0.00cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in program/steps/mail/func.inc in RoundCube Webmail before 0.8.0, when using the Larry skin, allows remote attackers to inject arbitrary web script or HTML via the email message subject.

  • CVE-2012-1253Jun 4, 2012
    risk 0.00cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 0.7, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via vectors involving an embedded image attachment.

  • CVE-2011-4078Nov 3, 2011
    risk 0.00cvss epss 0.02

    include/iniset.php in Roundcube Webmail 0.5.4 and earlier, when PHP 5.3.7 or 5.3.8 is used, allows remote attackers to trigger a GET request for an arbitrary URL, and cause a denial of service (resource consumption and inbox outage), via a Subject header containing only a URL, a…

  • CVE-2011-2937Sep 21, 2011
    risk 0.00cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in the UI messages functionality in Roundcube Webmail before 0.5.4 allows remote attackers to inject arbitrary web script or HTML via the _mbox parameter to the default URI.

  • CVE-2011-1492Apr 8, 2011
    risk 0.00cvss epss 0.02

    steps/utils/modcss.inc in Roundcube Webmail before 0.5.1 does not properly verify that a request is an expected request for an external Cascading Style Sheets (CSS) stylesheet, which allows remote authenticated users to trigger arbitrary outbound TCP connections from the server,…

  • CVE-2011-1491Apr 8, 2011
    risk 0.00cvss epss 0.02

    The login form in Roundcube Webmail before 0.5.1 does not properly handle a correctly authenticated but unintended login attempt, which makes it easier for remote authenticated users to obtain sensitive information by arranging for a victim to login to the attacker's account and…

  • CVE-2010-0464Jan 29, 2010
    risk 0.00cvss epss 0.02

    Roundcube 0.3.1 and earlier does not request that the web browser avoid DNS prefetching of domain names contained in e-mail messages, which makes it easier for remote attackers to determine the network location of the webmail user by logging DNS requests.

  • CVE-2009-4077Nov 25, 2009
    risk 0.00cvss epss 0.01

    Cross-site request forgery (CSRF) vulnerability in Roundcube Webmail 0.2.2 and earlier allows remote attackers to hijack the authentication of unspecified users for requests that send arbitrary emails via unspecified vectors, a different vulnerability than CVE-2009-4076.

  • CVE-2009-4076Nov 25, 2009
    risk 0.00cvss epss 0.01

    Cross-site request forgery (CSRF) vulnerability in Roundcube Webmail 0.2.2 and earlier allows remote attackers to hijack the authentication of unspecified users for requests that modify user information via unspecified vectors, a different vulnerability than CVE-2009-4077.

  • CVE-2009-0413Feb 3, 2009
    risk 0.00cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in RoundCube Webmail (roundcubemail) 0.2 stable allows remote attackers to inject arbitrary web script or HTML via the background attribute embedded in an HTML e-mail message.

  • CVE-2008-5620Dec 17, 2008
    risk 0.00cvss epss 0.03

    RoundCube Webmail (roundcubemail) before 0.2-beta allows remote attackers to cause a denial of service (memory consumption) via crafted size parameters that are used to create a large quota image.

  • CVE-2008-5619Dec 17, 2008
    risk 0.00cvss epss 0.54

    html2text.php in Chuggnutt HTML to Text Converter, as used in PHPMailer before 5.2.10, RoundCube Webmail (roundcubemail) 0.2-1.alpha and 0.2-3.beta, Mahara, and AtMail Open 1.03, allows remote attackers to execute arbitrary code via crafted input that is processed by the…

  • CVE-2007-6321Dec 12, 2007
    risk 0.00cvss epss 0.05

    Cross-site scripting (XSS) vulnerability in RoundCube webmail 0.1rc2, 2007-12-09, and earlier versions, when using Internet Explorer, allows remote attackers to inject arbitrary web script or HTML via style sheets containing expression commands.

  • CVE-2005-4368Dec 20, 2005
    risk 0.00cvss epss 0.01

    roundcube webmail Alpha, with a default high verbose level ($rcmail_config['debug_level'] = 1), allows remote attackers to obtain the full path of the application via an invalid_task parameter, which leaks the path in an error message.

Page 2 of 2