VYPR

Vendor CVEs

Roundcube

All CVEs

115 total · sorted by risk
  • CVE-2026-75003MedAug 17, 2026
    risk 0.31cvss 5.8epss 0.00

    In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed url() in a FuncIRI attribute of an SVG image could evade the remote image blocking, which may lead to information disclosure or privilege escalation.

  • CVE-2026-75000MedAug 17, 2026
    risk 0.31cvss 5.8epss 0.00

    In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper HTML/CSS sanitization of the SVG animate "by" attribute may lead to remote image blocking bypass, which in turn may lead to information disclosure or privilege escalation.

  • CVE-2026-54432MedJul 14, 2026
    risk 0.31cvss 4.7epss 0.00

    Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2 allows Stored Cross-Site Scripting (XSS). The issue occurs because the attachment MIME type is not properly escaped on the attachment-validation warning page.

  • CVE-2026-26079MedFeb 11, 2026
    risk 0.31cvss 4.7epss 0.00

    Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13 allows Cascading Style Sheets (CSS) injection, e.g., because comments are mishandled.

  • CVE-2026-75007MedAug 17, 2026
    risk 0.28cvss 5.4epss 0.00

    In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the LDAP search filter was subject to injection via unescaped %u/%fu/%d substitution, which may lead to information disclosure or privilege escalation.

  • CVE-2026-74999MedAug 17, 2026
    risk 0.28cvss 5.4epss 0.00

    In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the "Add to address book" action was subject to stored XSS.

  • CVE-2026-35540MedApr 3, 2026
    risk 0.28cvss 5.4epss 0.00

    An issue was discovered in Roundcube Webmail 1.6.0 before 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts.

  • CVE-2026-25916MedFeb 9, 2026
    risk 0.28cvss 4.3epss 0.01

    Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13, when "Block remote images" is used, does not block SVG feImage.

  • CVE-2019-10740MedApr 7, 2019
    risk 0.28cvss 4.3epss 0.01

    In Roundcube Webmail before 1.3.10, an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub-parts within a crafted multipart email. The encrypted part(s) can further be hidden using HTML/CSS or ASCII newline characters. This modified multipart email can…

  • CVE-2026-35545MedApr 3, 2026
    risk 0.27cvss 5.3epss 0.00

    An issue was discovered in Roundcube Webmail before 1.5.15 and 1.6.15. The remote image blocking feature can be bypassed via SVG content in an e-mail message. This may lead to information disclosure or access-control bypass. This involves the animate element with…

  • CVE-2026-35544MedApr 3, 2026
    risk 0.27cvss 5.3epss 0.00

    An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to a fixed-position mitigation bypass via the use of !important.

  • CVE-2026-35543MedApr 3, 2026
    risk 0.27cvss 5.3epss 0.00

    An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via SVG content (with animate attributes) in an e-mail message. This may lead to information disclosure or access-control bypass.

  • CVE-2026-35542MedApr 3, 2026
    risk 0.27cvss 5.3epss 0.00

    An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via a crafted background attribute of a BODY element in an e-mail message. This may lead to information disclosure or access-control bypass.

  • CVE-2026-48849MedMay 25, 2026
    risk 0.22cvss 4.4epss 0.00

    In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, an unsanitized subject field in the draft restored value could lead to stored XSS/HTML/CSS injection on shared mailboxes.

  • CVE-2026-75004MedAug 17, 2026
    risk 0.21cvss 4.3epss 0.00

    In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper rule name quoting could lead to managesieve_disabled_actions setting bypass via a crafted rule name in a Sieve script. This issue only affects Roundcube instances using the managesieve plugin.

  • CVE-2026-62642MedJul 14, 2026
    risk 0.21cvss 4.3epss 0.01

    In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, an infinite loop was discovered in the TNEF decoder, which may lead to denial of service upon opening an email with a TNEF attachment.

  • CVE-2026-62641MedJul 14, 2026
    risk 0.21cvss 4.3epss 0.00

    In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the TNEF decoder was subject to denial of service via a crafted compressed-RTF size.

  • CVE-2026-35541MedApr 3, 2026
    risk 0.20cvss 4.2epss 0.00

    An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Incorrect password comparison in the password plugin could lead to type confusion that allows a password change without knowing the old password.

  • CVE-2020-12641CriKEVMay 4, 2020
    risk 0.19cvss 9.8epss 0.84

    rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setting for im_convert_path or im_identify_path.

  • CVE-2023-5631MedKEVOct 18, 2023
    risk 0.18cvss 6.1epss 0.76

    Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a crafted SVG document because of program/lib/Roundcube/rcube_washtml.php behavior. This could allow a remote attacker to load arbitrary JavaScript code.

  • CVE-2020-13965MedKEVJun 9, 2020
    risk 0.18cvss 6.1epss 0.77

    An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is among the allowed types for a preview.

  • CVE-2026-48847LowMay 25, 2026
    risk 0.17cvss 3.7epss 0.00

    Roundcube Webmail 1.6.x before 1.6.16, and 1.7.x before 1.7.1 allows pre-authentication arbitrary file deletion via redis/memcache session poisoning bypass.

  • CVE-2026-35537LowApr 3, 2026
    risk 0.17cvss 3.7epss 0.00

    An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsafe deserialization in the redis/memcache session handler may lead to arbitrary file write operations by unauthenticated attackers via crafted session data.

  • CVE-2023-43770MedKEVSep 22, 2023
    risk 0.17cvss 6.1epss 0.58

    Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of program/lib/Roundcube/rcube_string_replacer.php behavior.

  • CVE-2021-44026CriKEVNov 19, 2021
    risk 0.15cvss 9.8epss 0.42

    Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.

  • CVE-2025-68461HigKEVDec 18, 2025
    risk 0.14cvss 7.2epss 0.27

    Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document.

  • CVE-2026-35538LowApr 3, 2026
    risk 0.13cvss 3.1epss 0.00

    An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsanitized IMAP SEARCH command arguments could lead to IMAP injection or CSRF bypass during mail search.

  • CVE-2020-12640CriMay 4, 2020
    risk 0.01cvss 9.8epss 0.07

    Roundcube Webmail before 1.4.4 allows attackers to include local files and execute code via directory traversal in a plugin name to rcube_plugin_api.php.

  • CVE-2008-5619Dec 17, 2008
    risk 0.01cvss —epss 0.59

    html2text.php in Chuggnutt HTML to Text Converter, as used in PHPMailer before 5.2.10, RoundCube Webmail (roundcubemail) 0.2-1.alpha and 0.2-3.beta, Mahara, and AtMail Open 1.03, allows remote attackers to execute arbitrary code via crafted input that is processed by the…

  • CVE-2026-9818May 28, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2025-68460HigDec 18, 2025
    risk 0.00cvss 7.2epss 0.00

    Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a information disclosure vulnerability in the HTML style sanitizer.

  • CVE-2024-37385CriJun 7, 2024
    risk 0.00cvss 9.8epss 0.01

    Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 on Windows allows command injection via im_convert_path and im_identify_path. NOTE: this issue exists because of an incomplete fix for CVE-2020-12641.

  • CVE-2024-37384MedJun 7, 2024
    risk 0.00cvss 6.1epss 0.01

    Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via list columns from user preferences.

  • CVE-2023-47272MedNov 6, 2023
    risk 0.00cvss 6.1epss 0.01

    Roundcube 1.5.x before 1.5.6 and 1.6.x before 1.6.5 allows XSS via a Content-Type or Content-Disposition header (used for attachment preview or download).

  • CVE-2021-46144MedJan 6, 2022
    risk 0.00cvss 6.1epss 0.01

    Roundcube before 1.4.13 and 1.5.x before 1.5.2 allows XSS via an HTML e-mail message with crafted Cascading Style Sheets (CSS) token sequences.

  • CVE-2021-44025MedNov 19, 2021
    risk 0.00cvss 6.1epss 0.01

    Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to XSS in handling an attachment's filename extension when displaying a MIME type warning message.

  • CVE-2021-26925MedFeb 9, 2021
    risk 0.00cvss 5.4epss 0.01

    Roundcube before 1.4.11 allows XSS via crafted Cascading Style Sheets (CSS) token sequences during HTML email rendering.

  • CVE-2020-16145MedAug 12, 2020
    risk 0.00cvss 6.1epss 0.02

    Roundcube Webmail before 1.3.15 and 1.4.8 allows stored XSS in HTML messages during message display via a crafted SVG document. This issue has been fixed in 1.4.8 and 1.3.15.

  • CVE-2020-15562MedJul 6, 2020
    risk 0.00cvss 6.1epss 0.02

    An issue was discovered in Roundcube Webmail before 1.2.11, 1.3.x before 1.3.14, and 1.4.x before 1.4.7. It allows XSS via a crafted HTML e-mail message, as demonstrated by a JavaScript payload in the xmlns (aka XML namespace) attribute of a HEAD element when an SVG element…

  • CVE-2020-13964MedJun 9, 2020
    risk 0.00cvss 6.1epss 0.01

    An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. include/rcmail_output_html.php allows XSS via the username template object.

  • CVE-2020-12626MedMay 4, 2020
    risk 0.00cvss 6.5epss 0.02

    An issue was discovered in Roundcube Webmail before 1.4.4. A CSRF attack can cause an authenticated user to be logged out because POST was not considered.

  • CVE-2020-12625MedMay 4, 2020
    risk 0.00cvss 6.1epss 0.03

    An issue was discovered in Roundcube Webmail before 1.4.4. There is a cross-site scripting (XSS) vulnerability in rcube_washtml.php because JavaScript code can occur in the CDATA of an HTML message.

  • CVE-2015-8105Nov 10, 2015
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in program/js/app.js in Roundcube webmail before 1.0.7 and 1.1.x before 1.1.3 allows remote authenticated users to inject arbitrary web script or HTML via the file name in a drag-n-drop file upload.

  • CVE-2015-1433Feb 3, 2015
    risk 0.00cvss —epss 0.03

    program/lib/Roundcube/rcube_washtml.php in Roundcube before 1.0.5 does not properly quote strings, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the style attribute in an email.

  • CVE-2014-9587Jan 15, 2015
    risk 0.00cvss —epss 0.02

    Multiple cross-site request forgery (CSRF) vulnerabilities in Roundcube Webmail before 1.0.4 allow remote attackers to hijack the authentication of unspecified victims via unknown vectors, related to (1) address book operations or the (2) ACL or (3) Managesieve plugins.

  • CVE-2013-1904Feb 8, 2014
    risk 0.00cvss —epss 0.02

    Absolute path traversal vulnerability in steps/mail/sendmail.inc in Roundcube Webmail before 0.7.3 and 0.8.x before 0.8.6 allows remote attackers to read arbitrary files via a full pathname in the _value parameter for the generic_message_footer setting in a save-perf action to…

  • CVE-2013-6172Nov 5, 2013
    risk 0.00cvss —epss 0.03

    steps/utils/save_pref.inc in Roundcube webmail before 0.8.7 and 0.9.x before 0.9.5 allows remote attackers to modify configuration settings via the _session parameter, which can be leveraged to read arbitrary files, conduct SQL injection attacks, and execute arbitrary code.

  • CVE-2013-5646Aug 29, 2013
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in Roundcube webmail 1.0-git allows remote authenticated users to inject arbitrary web script or HTML via the Name field of an addressbook group.

  • CVE-2013-5645Aug 29, 2013
    risk 0.00cvss —epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in Roundcube webmail before 0.9.3 allow user-assisted remote attackers to inject arbitrary web script or HTML via the body of a message visited in (1) new or (2) draft mode, related to compose.inc; and (3) might allow remote…

  • CVE-2012-6121Feb 24, 2013
    risk 0.00cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 0.8.5 allows remote attackers to inject arbitrary web script or HTML via a (1) data:text or (2) vbscript link.