Debian Roundcube vulnerabilities

85 known vulnerabilities affecting debian/roundcube.

Total CVEs
85
CISA KEV
11
actively exploited
Public exploits
10
Exploited in wild
9
Severity breakdown
CRITICAL4HIGH14MEDIUM46LOW21

Vulnerabilities

Page 2 of 5
CVE-2024-57004LOWCVSS 6.12024
CVE-2024-57004 [MEDIUM] CVE-2024-57004: roundcube - Cross-Site Scripting (XSS) vulnerability in Roundcube Webmail 1.6.9 allows remot... Cross-Site Scripting (XSS) vulnerability in Roundcube Webmail 1.6.9 allows remote authenticated users to upload a malicious file as an email attachment, leading to the triggering of the XSS by visiting the SENT session. Scope: local bookworm: open bullseye: open forky: open sid: open trixie: open
debian
CVE-2023-5631MEDIUMCVSS 6.1KEVfixed in roundcube 1.6.4+dfsg-1~deb12u1 (bookworm)2023
CVE-2023-5631 [MEDIUM] CVE-2023-5631: roundcube - Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows store... Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a crafted SVG document because of program/lib/Roundcube/rcube_washtml.php behavior. This could allow a remote attacker to load arbitrary JavaScript code. Scope: local bookworm: resolved (fixed in 1.6.4+dfsg-1~deb12u1) bullseye: resolved (fixed in 1
debian
CVE-2023-47272MEDIUMCVSS 6.1fixed in roundcube 1.6.5+dfsg-1~deb12u1 (bookworm)2023
CVE-2023-47272 [MEDIUM] CVE-2023-47272: roundcube - Roundcube 1.5.x before 1.5.6 and 1.6.x before 1.6.5 allows XSS via a Content-Typ... Roundcube 1.5.x before 1.5.6 and 1.6.x before 1.6.5 allows XSS via a Content-Type or Content-Disposition header (used for attachment preview or download). Scope: local bookworm: resolved (fixed in 1.6.5+dfsg-1~deb12u1) bullseye: resolved (fixed in 1.4.15+dfsg.1-1~deb11u2) forky: resolved (fixed in 1.6.5+dfsg-1) sid: resolved (fixed in 1.6.5+dfsg-1) trixie: resol
debian
CVE-2023-43770MEDIUMCVSS 6.1KEVfixed in roundcube 1.6.3+dfsg-1~deb12u1 (bookworm)2023
CVE-2023-43770 [MEDIUM] CVE-2023-43770: roundcube - Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS v... Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of program/lib/Roundcube/rcube_string_replacer.php behavior. Scope: local bookworm: resolved (fixed in 1.6.3+dfsg-1~deb12u1) bullseye: resolved (fixed in 1.4.14+dfsg.1-1~deb11u1) forky: resolved (fixed in 1.6.3+dfsg-1) sid: res
debian
CVE-2021-44026CRITICALCVSS 9.8KEVfixed in roundcube 1.5.0+dfsg.1-1 (bookworm)2021
CVE-2021-44026 [CRITICAL] CVE-2021-44026: roundcube - Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL inje... Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params. Scope: local bookworm: resolved (fixed in 1.5.0+dfsg.1-1) bullseye: resolved (fixed in 1.4.12+dfsg.1-1~deb11u1) forky: resolved (fixed in 1.5.0+dfsg.1-1) sid: resolved (fixed in 1.5.0+dfsg.1-1) trixie: resolved (fixed in 1.5.0+dfsg.1-1)
debian
CVE-2021-46144MEDIUMCVSS 6.1fixed in roundcube 1.6.0+dfsg-1 (bookworm)2021
CVE-2021-46144 [MEDIUM] CVE-2021-46144: roundcube - Roundcube before 1.4.13 and 1.5.x before 1.5.2 allows XSS via an HTML e-mail mes... Roundcube before 1.4.13 and 1.5.x before 1.5.2 allows XSS via an HTML e-mail message with crafted Cascading Style Sheets (CSS) token sequences. Scope: local bookworm: resolved (fixed in 1.6.0+dfsg-1) bullseye: resolved (fixed in 1.4.13+dfsg.1-1~deb11u1) forky: resolved (fixed in 1.6.0+dfsg-1) sid: resolved (fixed in 1.6.0+dfsg-1) trixie: resolved (fixed in 1.6.0
debian
CVE-2021-26925MEDIUMCVSS 5.4fixed in roundcube 1.4.11+dfsg.1-1 (bookworm)2021
CVE-2021-26925 [MEDIUM] CVE-2021-26925: roundcube - Roundcube before 1.4.11 allows XSS via crafted Cascading Style Sheets (CSS) toke... Roundcube before 1.4.11 allows XSS via crafted Cascading Style Sheets (CSS) token sequences during HTML email rendering. Scope: local bookworm: resolved (fixed in 1.4.11+dfsg.1-1) bullseye: resolved (fixed in 1.4.11+dfsg.1-1) forky: resolved (fixed in 1.4.11+dfsg.1-1) sid: resolved (fixed in 1.4.11+dfsg.1-1) trixie: resolved (fixed in 1.4.11+dfsg.1-1)
debian
CVE-2021-44025MEDIUMCVSS 6.1fixed in roundcube 1.5.0+dfsg.1-1 (bookworm)2021
CVE-2021-44025 [MEDIUM] CVE-2021-44025: roundcube - Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to XSS in handling an a... Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to XSS in handling an attachment's filename extension when displaying a MIME type warning message. Scope: local bookworm: resolved (fixed in 1.5.0+dfsg.1-1) bullseye: resolved (fixed in 1.4.12+dfsg.1-1~deb11u1) forky: resolved (fixed in 1.5.0+dfsg.1-1) sid: resolved (fixed in 1.5.0+dfsg.1-1) trixie: resolv
debian
CVE-2020-13964MEDIUMCVSS 6.1fixed in roundcube 1.4.5+dfsg.1-1 (bookworm)2020
CVE-2020-13964 [MEDIUM] CVE-2020-13964: roundcube - An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.... An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. include/rcmail_output_html.php allows XSS via the username template object. Scope: local bookworm: resolved (fixed in 1.4.5+dfsg.1-1) bullseye: resolved (fixed in 1.4.5+dfsg.1-1) forky: resolved (fixed in 1.4.5+dfsg.1-1) sid: resolved (fixed in 1.4.5+dfsg.1-1) trixie: resolved (fi
debian
CVE-2020-18670MEDIUMCVSS 5.4fixed in roundcube 1.4.5+dfsg.1-1 (bookworm)2020
CVE-2020-18670 [MEDIUM] CVE-2020-18670: roundcube - Cross Site Scripting (XSS) vulneraibility in Roundcube mail .4.4 via database ho... Cross Site Scripting (XSS) vulneraibility in Roundcube mail .4.4 via database host and user in /installer/test.php. Scope: local bookworm: resolved (fixed in 1.4.5+dfsg.1-1) bullseye: resolved (fixed in 1.4.5+dfsg.1-1) forky: resolved (fixed in 1.4.5+dfsg.1-1) sid: resolved (fixed in 1.4.5+dfsg.1-1) trixie: resolved (fixed in 1.4.5+dfsg.1-1)
debian
CVE-2020-15562MEDIUMCVSS 6.1fixed in roundcube 1.4.7+dfsg.1-1 (bookworm)2020
CVE-2020-15562 [MEDIUM] CVE-2020-15562: roundcube - An issue was discovered in Roundcube Webmail before 1.2.11, 1.3.x before 1.3.14,... An issue was discovered in Roundcube Webmail before 1.2.11, 1.3.x before 1.3.14, and 1.4.x before 1.4.7. It allows XSS via a crafted HTML e-mail message, as demonstrated by a JavaScript payload in the xmlns (aka XML namespace) attribute of a HEAD element when an SVG element exists. Scope: local bookworm: resolved (fixed in 1.4.7+dfsg.1-1) bullseye: resolved (fix
debian
CVE-2020-13965MEDIUMCVSS 6.1KEVfixed in roundcube 1.4.5+dfsg.1-1 (bookworm)2020
CVE-2020-13965 [MEDIUM] CVE-2020-13965: roundcube - An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.... An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is among the allowed types for a preview. Scope: local bookworm: resolved (fixed in 1.4.5+dfsg.1-1) bullseye: resolved (fixed in 1.4.5+dfsg.1-1) forky: resolved (fixed in 1.4.5+dfsg.1-1) sid: resolved (fixed in 1.4.5+dfs
debian
CVE-2020-18671MEDIUMCVSS 5.4fixed in roundcube 1.4.5+dfsg.1-1 (bookworm)2020
CVE-2020-18671 [MEDIUM] CVE-2020-18671: roundcube - Cross Site Scripting (XSS) vulnerability in Roundcube Mail <=1.4.4 via smtp conf... Cross Site Scripting (XSS) vulnerability in Roundcube Mail <=1.4.4 via smtp config in /installer/test.php. Scope: local bookworm: resolved (fixed in 1.4.5+dfsg.1-1) bullseye: resolved (fixed in 1.4.5+dfsg.1-1) forky: resolved (fixed in 1.4.5+dfsg.1-1) sid: resolved (fixed in 1.4.5+dfsg.1-1) trixie: resolved (fixed in 1.4.5+dfsg.1-1)
debian
CVE-2020-12626MEDIUMCVSS 6.5fixed in roundcube 1.4.4+dfsg.1-1 (bookworm)2020
CVE-2020-12626 [MEDIUM] CVE-2020-12626: roundcube - An issue was discovered in Roundcube Webmail before 1.4.4. A CSRF attack can cau... An issue was discovered in Roundcube Webmail before 1.4.4. A CSRF attack can cause an authenticated user to be logged out because POST was not considered. Scope: local bookworm: resolved (fixed in 1.4.4+dfsg.1-1) bullseye: resolved (fixed in 1.4.4+dfsg.1-1) forky: resolved (fixed in 1.4.4+dfsg.1-1) sid: resolved (fixed in 1.4.4+dfsg.1-1) trixie: resolved (fixed
debian
CVE-2020-16145MEDIUMCVSS 6.1fixed in roundcube 1.4.8+dfsg.1-1 (bookworm)2020
CVE-2020-16145 [MEDIUM] CVE-2020-16145: roundcube - Roundcube Webmail before 1.3.15 and 1.4.8 allows stored XSS in HTML messages dur... Roundcube Webmail before 1.3.15 and 1.4.8 allows stored XSS in HTML messages during message display via a crafted SVG document. This issue has been fixed in 1.4.8 and 1.3.15. Scope: local bookworm: resolved (fixed in 1.4.8+dfsg.1-1) bullseye: resolved (fixed in 1.4.8+dfsg.1-1) forky: resolved (fixed in 1.4.8+dfsg.1-1) sid: resolved (fixed in 1.4.8+dfsg.1-1) trix
debian
CVE-2020-12625MEDIUMCVSS 6.1fixed in roundcube 1.4.4+dfsg.1-1 (bookworm)2020
CVE-2020-12625 [MEDIUM] CVE-2020-12625: roundcube - An issue was discovered in Roundcube Webmail before 1.4.4. There is a cross-site... An issue was discovered in Roundcube Webmail before 1.4.4. There is a cross-site scripting (XSS) vulnerability in rcube_washtml.php because JavaScript code can occur in the CDATA of an HTML message. Scope: local bookworm: resolved (fixed in 1.4.4+dfsg.1-1) bullseye: resolved (fixed in 1.4.4+dfsg.1-1) forky: resolved (fixed in 1.4.4+dfsg.1-1) sid: resolved (fixed
debian
CVE-2020-35730MEDIUMCVSS 6.1KEVfixed in roundcube 1.4.10+dfsg.1-1 (bookworm)2020
CVE-2020-35730 [MEDIUM] CVE-2020-35730: roundcube - An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3... An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attacker can send a plain text e-mail message, with JavaScript in a link reference element that is mishandled by linkref_addindex in rcube_string_replacer.php. Scope: local bookworm: resolved (fixed in 1.4.10+dfsg.1-1) bullseye: resolved (fixed in 1.
debian
CVE-2020-12641LOWCVSS 9.8KEVPoCfixed in roundcube 1.4.4+dfsg.1-1 (bookworm)2020
CVE-2020-12641 [CRITICAL] CVE-2020-12641: roundcube - rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute ar... rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setting for im_convert_path or im_identify_path. Scope: local bookworm: resolved (fixed in 1.4.4+dfsg.1-1) bullseye: resolved (fixed in 1.4.4+dfsg.1-1) forky: resolved (fixed in 1.4.4+dfsg.1-1) sid: resolved (fixed in 1.4.4+d
debian
CVE-2020-12640LOWCVSS 9.8fixed in roundcube 1.4.4+dfsg.1-1 (bookworm)2020
CVE-2020-12640 [CRITICAL] CVE-2020-12640: roundcube - Roundcube Webmail before 1.4.4 allows attackers to include local files and execu... Roundcube Webmail before 1.4.4 allows attackers to include local files and execute code via directory traversal in a plugin name to rcube_plugin_api.php. Scope: local bookworm: resolved (fixed in 1.4.4+dfsg.1-1) bullseye: resolved (fixed in 1.4.4+dfsg.1-1) forky: resolved (fixed in 1.4.4+dfsg.1-1) sid: resolved (fixed in 1.4.4+dfsg.1-1) trixie: resolved (fixed
debian
CVE-2019-10740MEDIUMCVSS 4.3fixed in roundcube 1.3.10+dfsg.1-1 (bookworm)2019
CVE-2019-10740 [MEDIUM] CVE-2019-10740: roundcube - In Roundcube Webmail before 1.3.10, an attacker in possession of S/MIME or PGP e... In Roundcube Webmail before 1.3.10, an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub-parts within a crafted multipart email. The encrypted part(s) can further be hidden using HTML/CSS or ASCII newline characters. This modified multipart email can be re-sent by the attacker to the intended receiver. If the receiver replies to this
debian