Debian Roundcube vulnerabilities
85 known vulnerabilities affecting debian/roundcube.
Total CVEs
85
CISA KEV
11
actively exploited
Public exploits
10
Exploited in wild
9
Severity breakdown
CRITICAL4HIGH14MEDIUM46LOW21
Vulnerabilities
Page 1 of 5
CVE-2026-25916MEDIUMCVSS 4.3fixed in roundcube 1.6.5+dfsg-1+deb12u7 (bookworm)2026
CVE-2026-25916 [MEDIUM] CVE-2026-25916: roundcube - Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13, when "Block remote images...
Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13, when "Block remote images" is used, does not block SVG feImage.
Scope: local
bookworm: resolved (fixed in 1.6.5+dfsg-1+deb12u7)
bullseye: resolved (fixed in 1.4.15+dfsg.1-1+deb11u7)
forky: resolved (fixed in 1.6.13+dfsg-1)
sid: resolved (fixed in 1.6.13+dfsg-1)
trixie: resolved (fixed in 1.6.13+dfsg-0+deb13u
debian
CVE-2026-35544MEDIUMCVSS 5.3fixed in roundcube 1.6.5+dfsg-1+deb12u8 (bookworm)2026
CVE-2026-35544 [MEDIUM] CVE-2026-35544: roundcube - An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Insuffici...
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to a fixed-position mitigation bypass via the use of !important.
Scope: local
bookworm: resolved (fixed in 1.6.5+dfsg-1+deb12u8)
bullseye: resolved (fixed in 1.4.15+dfsg.1-1+deb11u8)
forky: resolved (fixed
debian
CVE-2026-35540MEDIUMCVSS 5.4fixed in roundcube 1.6.5+dfsg-1+deb12u8 (bookworm)2026
CVE-2026-35540 [MEDIUM] CVE-2026-35540: roundcube - An issue was discovered in Roundcube Webmail 1.6.0 before 1.6.14. Insufficient C...
An issue was discovered in Roundcube Webmail 1.6.0 before 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts.
Scope: local
bookworm: resolved (fixed in 1.6.5+dfsg-1+deb12u8)
bullseye: resolved (fixed in 1.4.15+dfsg.1-1+deb11u8)
f
debian
CVE-2026-35542MEDIUMCVSS 5.3fixed in roundcube 1.6.5+dfsg-1+deb12u8 (bookworm)2026
CVE-2026-35542 [MEDIUM] CVE-2026-35542: roundcube - An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remot...
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via a crafted background attribute of a BODY element in an e-mail message. This may lead to information disclosure or access-control bypass.
Scope: local
bookworm: resolved (fixed in 1.6.5+dfsg-1+deb12u8)
bullseye: resolved (fixed in 1.4.15+df
debian
CVE-2026-35539MEDIUMCVSS 6.1fixed in roundcube 1.6.5+dfsg-1+deb12u8 (bookworm)2026
CVE-2026-35539 [MEDIUM] CVE-2026-35539: roundcube - An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. XSS exist...
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. XSS exists because of insufficient HTML attachment sanitization in preview mode. A victim must preview a text/html attachment.
Scope: local
bookworm: resolved (fixed in 1.6.5+dfsg-1+deb12u8)
bullseye: resolved (fixed in 1.4.15+dfsg.1-1+deb11u8)
forky: resolved (fixed in 1.6.14+dfsg-1)
sid: re
debian
CVE-2026-26079MEDIUMCVSS 4.7fixed in roundcube 1.6.5+dfsg-1+deb12u7 (bookworm)2026
CVE-2026-26079 [MEDIUM] CVE-2026-26079: roundcube - Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13 allows Cascading Style She...
Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13 allows Cascading Style Sheets (CSS) injection, e.g., because comments are mishandled.
Scope: local
bookworm: resolved (fixed in 1.6.5+dfsg-1+deb12u7)
bullseye: resolved (fixed in 1.4.15+dfsg.1-1+deb11u7)
forky: resolved (fixed in 1.6.13+dfsg-1)
sid: resolved (fixed in 1.6.13+dfsg-1)
trixie: resolved (fixed in
debian
CVE-2026-35543MEDIUMCVSS 5.3fixed in roundcube 1.6.5+dfsg-1+deb12u8 (bookworm)2026
CVE-2026-35543 [MEDIUM] CVE-2026-35543: roundcube - An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remot...
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via SVG content (with animate attributes) in an e-mail message. This may lead to information disclosure or access-control bypass.
Scope: local
bookworm: resolved (fixed in 1.6.5+dfsg-1+deb12u8)
bullseye: resolved (fixed in 1.4.15+dfsg.1-1+deb1
debian
CVE-2026-35545MEDIUMCVSS 5.3fixed in roundcube 1.6.5+dfsg-1+deb12u8 (bookworm)2026
CVE-2026-35545 [MEDIUM] CVE-2026-35545: roundcube - An issue was discovered in Roundcube Webmail before 1.5.15 and 1.6.15. The remot...
An issue was discovered in Roundcube Webmail before 1.5.15 and 1.6.15. The remote image blocking feature can be bypassed via SVG content in an e-mail message. This may lead to information disclosure or access-control bypass. This involves the animate element with attributeName=fill/filter/stroke.
Scope: local
bookworm: resolved (fixed in 1.6.5+dfsg-1+deb12u8)
bu
debian
CVE-2026-35541MEDIUMCVSS 4.2fixed in roundcube 1.6.5+dfsg-1+deb12u8 (bookworm)2026
CVE-2026-35541 [MEDIUM] CVE-2026-35541: roundcube - An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Incorrect...
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Incorrect password comparison in the password plugin could lead to type confusion that allows a password change without knowing the old password.
Scope: local
bookworm: resolved (fixed in 1.6.5+dfsg-1+deb12u8)
bullseye: resolved (fixed in 1.4.15+dfsg.1-1+deb11u8)
forky: resolved (fixed in 1.6
debian
CVE-2026-35537LOWCVSS 3.7fixed in roundcube 1.6.5+dfsg-1+deb12u8 (bookworm)2026
CVE-2026-35537 [LOW] CVE-2026-35537: roundcube - An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsafe de...
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsafe deserialization in the redis/memcache session handler may lead to arbitrary file write operations by unauthenticated attackers via crafted session data.
Scope: local
bookworm: resolved (fixed in 1.6.5+dfsg-1+deb12u8)
bullseye: resolved
forky: resolved (fixed in 1.6.14+dfsg-1)
sid: resolve
debian
CVE-2026-35538LOWCVSS 3.1fixed in roundcube 1.6.5+dfsg-1+deb12u8 (bookworm)2026
CVE-2026-35538 [LOW] CVE-2026-35538: roundcube - An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsanitiz...
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsanitized IMAP SEARCH command arguments could lead to IMAP injection or CSRF bypass during mail search.
Scope: local
bookworm: resolved (fixed in 1.6.5+dfsg-1+deb12u8)
bullseye: resolved (fixed in 1.4.15+dfsg.1-1+deb11u8)
forky: resolved (fixed in 1.6.14+dfsg-1)
sid: resolved (fixed in 1.6.14+
debian
CVE-2025-49113CRITICALCVSS 9.9KEVPoCfixed in roundcube 1.6.5+dfsg-1+deb12u5 (bookworm)2025
CVE-2025-49113 [CRITICAL] CVE-2025-49113: roundcube - Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execu...
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP Object Deserialization.
Scope: local
bookworm: resolved (fixed in 1.6.5+dfsg-1+deb12u5)
bullseye: resolved (fixed in 1.4.15+dfsg.1-1+deb11u5)
for
debian
CVE-2025-68461HIGHCVSS 7.2KEVfixed in roundcube 1.6.5+dfsg-1+deb12u6 (bookworm)2025
CVE-2025-68461 [HIGH] CVE-2025-68461: roundcube - Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-S...
Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document.
Scope: local
bookworm: resolved (fixed in 1.6.5+dfsg-1+deb12u6)
bullseye: resolved (fixed in 1.4.15+dfsg.1-1+deb11u6)
forky: resolved (fixed in 1.6.12+dfsg-1)
sid: resolved (fixed in 1.6.12+dfsg-1)
trixie: resolved (f
debian
CVE-2025-68460HIGHCVSS 7.2fixed in roundcube 1.6.5+dfsg-1+deb12u6 (bookworm)2025
CVE-2025-68460 [HIGH] CVE-2025-68460: roundcube - Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a information ...
Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a information disclosure vulnerability in the HTML style sanitizer.
Scope: local
bookworm: resolved (fixed in 1.6.5+dfsg-1+deb12u6)
bullseye: resolved (fixed in 1.4.15+dfsg.1-1+deb11u6)
forky: resolved (fixed in 1.6.12+dfsg-1)
sid: resolved (fixed in 1.6.12+dfsg-1)
trixie: resolved (fixed in 1.6.12+
debian
CVE-2024-42008CRITICALCVSS 9.3fixed in roundcube 1.6.5+dfsg-1+deb12u3 (bookworm)2024
CVE-2024-42008 [CRITICAL] CVE-2024-42008: roundcube - A Cross-Site Scripting vulnerability in rcmail_action_mail_get->run() in Roundcu...
A Cross-Site Scripting vulnerability in rcmail_action_mail_get->run() in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a malicious e-mail attachment served with a dangerous Content-Type header.
Scope: local
bookworm: resolved (fixed in 1.6.5+dfsg-1+deb12u3)
bullseye: resolved (fixed in 1.4.15+
debian
CVE-2024-42009CRITICALCVSS 9.3KEVPoCfixed in roundcube 1.6.5+dfsg-1+deb12u3 (bookworm)2024
CVE-2024-42009 [CRITICAL] CVE-2024-42009: roundcube - A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x throug...
A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a crafted e-mail message that abuses a Desanitization issue in message_body() in program/actions/mail/show.php.
Scope: local
bookworm: resolved (fixed in 1.6.5+dfsg-1+deb12u3)
bullseye: resolved (fixed in 1.4
debian
CVE-2024-42010HIGHCVSS 7.5fixed in roundcube 1.6.5+dfsg-1+deb12u3 (bookworm)2024
CVE-2024-42010 [HIGH] CVE-2024-42010: roundcube - mod_css_styles in Roundcube through 1.5.7 and 1.6.x through 1.6.7 insufficiently...
mod_css_styles in Roundcube through 1.5.7 and 1.6.x through 1.6.7 insufficiently filters Cascading Style Sheets (CSS) token sequences in rendered e-mail messages, allowing a remote attacker to obtain sensitive information.
Scope: local
bookworm: resolved (fixed in 1.6.5+dfsg-1+deb12u3)
bullseye: resolved (fixed in 1.4.15+dfsg.1-1+deb11u4)
forky: resolved (fixed in
debian
CVE-2024-37384MEDIUMCVSS 6.1fixed in roundcube 1.6.5+dfsg-1+deb12u2 (bookworm)2024
CVE-2024-37384 [MEDIUM] CVE-2024-37384: roundcube - Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via list column...
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via list columns from user preferences.
Scope: local
bookworm: resolved (fixed in 1.6.5+dfsg-1+deb12u2)
bullseye: resolved (fixed in 1.4.15+dfsg.1-1+deb11u3)
forky: resolved (fixed in 1.6.7+dfsg-1)
sid: resolved (fixed in 1.6.7+dfsg-1)
trixie: resolved (fixed in 1.6.7+dfsg-1)
debian
CVE-2024-37383MEDIUMCVSS 6.1KEVPoCfixed in roundcube 1.6.5+dfsg-1+deb12u2 (bookworm)2024
CVE-2024-37383 [MEDIUM] CVE-2024-37383: roundcube - Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate...
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.
Scope: local
bookworm: resolved (fixed in 1.6.5+dfsg-1+deb12u2)
bullseye: resolved (fixed in 1.4.15+dfsg.1-1+deb11u3)
forky: resolved (fixed in 1.6.7+dfsg-1)
sid: resolved (fixed in 1.6.7+dfsg-1)
trixie: resolved (fixed in 1.6.7+dfsg-1)
debian
CVE-2024-37385LOWCVSS 9.82024
CVE-2024-37385 [CRITICAL] CVE-2024-37385: roundcube - Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 on Windows allows command ...
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 on Windows allows command injection via im_convert_path and im_identify_path. NOTE: this issue exists because of an incomplete fix for CVE-2020-12641.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
debian
1 / 5Next →