Roundcube Webmail vulnerabilities
80 known vulnerabilities affecting roundcube/webmail.
Total CVEs
80
CISA KEV
11
actively exploited
Public exploits
9
Exploited in wild
9
Severity breakdown
CRITICAL7HIGH17MEDIUM50LOW6
Vulnerabilities
Page 2 of 4
CVE-2023-47272MEDIUMCVSS 6.1≥ 1.5.0, < 1.5.6≥ 1.6.0, < 1.6.52023-11-06
CVE-2023-47272 [MEDIUM] CWE-79 CVE-2023-47272: Roundcube 1.5.x before 1.5.6 and 1.6.x before 1.6.5 allows XSS via a Content-Type or Content-Disposi
Roundcube 1.5.x before 1.5.6 and 1.6.x before 1.6.5 allows XSS via a Content-Type or Content-Disposition header (used for attachment preview or download).
nvd
CVE-2023-5631MEDIUMCVSS 5.4KEVfixed in 1.4.15≥ 1.5.0, < 1.5.5+1 more2023-10-18
CVE-2023-5631 [MEDIUM] CWE-79 CVE-2023-5631: Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-
Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a crafted SVG document because of program/lib/Roundcube/rcube_washtml.php behavior. This could allow a remote attacker
to load arbitrary JavaScript code.
nvd
CVE-2023-43770MEDIUMCVSS 6.1KEVfixed in 1.4.14≥ 1.5.0, < 1.5.4+1 more2023-09-22
CVE-2023-43770 [MEDIUM] CWE-79 CVE-2023-43770: Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail
Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of program/lib/Roundcube/rcube_string_replacer.php behavior.
nvd
CVE-2021-44026CRITICALCVSS 9.8KEVfixed in 1.3.17≥ 1.4.0, < 1.4.122021-11-19
CVE-2021-44026 [CRITICAL] CWE-89 CVE-2021-44026: Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or
Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.
nvd
CVE-2021-44025MEDIUMCVSS 6.1fixed in 1.3.17≥ 1.4.0, < 1.4.122021-11-19
CVE-2021-44025 [MEDIUM] CWE-79 CVE-2021-44025: Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to XSS in handling an attachment's filename
Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to XSS in handling an attachment's filename extension when displaying a MIME type warning message.
nvd
CVE-2020-18671MEDIUMCVSS 5.4≤ 1.4.42021-06-24
CVE-2020-18671 [MEDIUM] CWE-79 CVE-2020-18671: Cross Site Scripting (XSS) vulnerability in Roundcube Mail <=1.4.4 via smtp config in /installer/tes
Cross Site Scripting (XSS) vulnerability in Roundcube Mail <=1.4.4 via smtp config in /installer/test.php.
nvd
CVE-2020-18670MEDIUMCVSS 5.4v1.4.42021-06-24
CVE-2020-18670 [MEDIUM] CWE-79 CVE-2020-18670: Cross Site Scripting (XSS) vulneraibility in Roundcube mail .4.4 via database host and user in /inst
Cross Site Scripting (XSS) vulneraibility in Roundcube mail .4.4 via database host and user in /installer/test.php.
nvd
CVE-2021-26925MEDIUMCVSS 5.4fixed in 1.4.112021-02-09
CVE-2021-26925 [MEDIUM] CWE-79 CVE-2021-26925: Roundcube before 1.4.11 allows XSS via crafted Cascading Style Sheets (CSS) token sequences during H
Roundcube before 1.4.11 allows XSS via crafted Cascading Style Sheets (CSS) token sequences during HTML email rendering.
nvd
CVE-2020-35730MEDIUMCVSS 6.1KEVfixed in 1.2.13≥ 1.3.0, < 1.3.16+1 more2020-12-28
CVE-2020-35730 [MEDIUM] CWE-79 CVE-2020-35730: An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x befor
An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attacker can send a plain text e-mail message, with JavaScript in a link reference element that is mishandled by linkref_addindex in rcube_string_replacer.php.
nvd
CVE-2020-16145MEDIUMCVSS 6.1fixed in 1.3.15≥ 1.4.0, < 1.4.82020-08-12
CVE-2020-16145 [MEDIUM] CWE-79 CVE-2020-16145: Roundcube Webmail before 1.3.15 and 1.4.8 allows stored XSS in HTML messages during message display
Roundcube Webmail before 1.3.15 and 1.4.8 allows stored XSS in HTML messages during message display via a crafted SVG document. This issue has been fixed in 1.4.8 and 1.3.15.
nvd
CVE-2020-15562MEDIUMCVSS 6.1fixed in 1.2.11≥ 1.3.0, < 1.3.14+1 more2020-07-06
CVE-2020-15562 [MEDIUM] CWE-79 CVE-2020-15562: An issue was discovered in Roundcube Webmail before 1.2.11, 1.3.x before 1.3.14, and 1.4.x before 1.
An issue was discovered in Roundcube Webmail before 1.2.11, 1.3.x before 1.3.14, and 1.4.x before 1.4.7. It allows XSS via a crafted HTML e-mail message, as demonstrated by a JavaScript payload in the xmlns (aka XML namespace) attribute of a HEAD element when an SVG element exists.
nvd
CVE-2020-13965MEDIUMCVSS 6.1KEVfixed in 1.3.12≥ 1.4.0, < 1.4.52020-06-09
CVE-2020-13965 [MEDIUM] CWE-79 CVE-2020-13965: An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via
An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is among the allowed types for a preview.
nvd
CVE-2020-13964MEDIUMCVSS 6.1fixed in 1.3.12≥ 1.4.0, < 1.4.52020-06-09
CVE-2020-13964 [MEDIUM] CWE-79 CVE-2020-13964: An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. include/rcmail_ou
An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. include/rcmail_output_html.php allows XSS via the username template object.
nvd
CVE-2020-12641CRITICALCVSS 9.8KEVPoC≥ 1.2.0, < 1.2.10≥ 1.3.0, < 1.3.11+1 more2020-05-04
CVE-2020-12641 [CRITICAL] CWE-78 CVE-2020-12641: rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via she
rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setting for im_convert_path or im_identify_path.
nvd
CVE-2020-12640CRITICALCVSS 9.8≥ 1.2.0, < 1.2.10≥ 1.3.0, < 1.3.11+1 more2020-05-04
CVE-2020-12640 [CRITICAL] CWE-22 CVE-2020-12640: Roundcube Webmail before 1.4.4 allows attackers to include local files and execute code via director
Roundcube Webmail before 1.4.4 allows attackers to include local files and execute code via directory traversal in a plugin name to rcube_plugin_api.php.
nvd
CVE-2020-12626MEDIUMCVSS 6.5fixed in 1.4.42020-05-04
CVE-2020-12626 [MEDIUM] CWE-352 CVE-2020-12626: An issue was discovered in Roundcube Webmail before 1.4.4. A CSRF attack can cause an authenticated
An issue was discovered in Roundcube Webmail before 1.4.4. A CSRF attack can cause an authenticated user to be logged out because POST was not considered.
nvd
CVE-2020-12625MEDIUMCVSS 6.1fixed in 1.4.42020-05-04
CVE-2020-12625 [MEDIUM] CWE-79 CVE-2020-12625: An issue was discovered in Roundcube Webmail before 1.4.4. There is a cross-site scripting (XSS) vul
An issue was discovered in Roundcube Webmail before 1.4.4. There is a cross-site scripting (XSS) vulnerability in rcube_washtml.php because JavaScript code can occur in the CDATA of an HTML message.
nvd
CVE-2019-15237HIGHCVSS 7.4≤ 1.3.92019-08-20
CVE-2019-15237 [HIGH] CVE-2019-15237: Roundcube Webmail through 1.3.9 mishandles Punycode xn-- domain names, leading to homograph attacks.
Roundcube Webmail through 1.3.9 mishandles Punycode xn-- domain names, leading to homograph attacks.
nvd
CVE-2019-10740MEDIUMCVSS 4.3fixed in 1.3.102019-04-07
CVE-2019-10740 [MEDIUM] CWE-319 CVE-2019-10740: In Roundcube Webmail before 1.3.10, an attacker in possession of S/MIME or PGP encrypted emails can
In Roundcube Webmail before 1.3.10, an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub-parts within a crafted multipart email. The encrypted part(s) can further be hidden using HTML/CSS or ASCII newline characters. This modified multipart email can be re-sent by the attacker to the intended receiver. If the receiver repl
nvd
CVE-2018-19205HIGHCVSS 7.5fixed in 1.3.72018-11-12
CVE-2018-19205 [HIGH] CVE-2018-19205: Roundcube before 1.3.7 mishandles GnuPG MDC integrity-protection warnings, which makes it easier for
Roundcube before 1.3.7 mishandles GnuPG MDC integrity-protection warnings, which makes it easier for attackers to obtain sensitive information, a related issue to CVE-2017-17688. This is associated with plugins/enigma/lib/enigma_driver_gnupg.php.
nvd