Roundcube Webmail vulnerabilities

80 known vulnerabilities affecting roundcube/webmail.

Total CVEs
80
CISA KEV
11
actively exploited
Public exploits
9
Exploited in wild
9
Severity breakdown
CRITICAL7HIGH17MEDIUM50LOW6

Vulnerabilities

Page 3 of 4
CVE-2018-19206MEDIUMCVSS 6.1fixed in 1.3.82018-11-12
CVE-2018-19206 [MEDIUM] CWE-79 CVE-2018-19206: steps/mail/func.inc in Roundcube before 1.3.8 has XSS via crafted use of <svg><style>, as demonstrat steps/mail/func.inc in Roundcube before 1.3.8 has XSS via crafted use of , as demonstrated by an onload attribute in a BODY element, within an HTML attachment.
nvd
CVE-2018-9846HIGHCVSS 8.8≥ 1.2.0, ≤ 1.3.52018-04-07
CVE-2018-9846 [HIGH] CWE-20 CVE-2018-9846: In Roundcube from versions 1.2.0 to 1.3.5, with the archive plugin enabled and configured, it's poss In Roundcube from versions 1.2.0 to 1.3.5, with the archive plugin enabled and configured, it's possible to exploit the unsanitized, user-controlled "_uid" parameter (in an archive.php _task=mail&_mbox=INBOX&_action=plugin.move2archive request) to perform an MX (IMAP) injection attack by placing an IMAP command after a %0d%0a sequence. NOTE: this is less
nvd
CVE-2018-1000071HIGHCVSS 7.5≤ 1.3.42018-03-13
CVE-2018-1000071 [HIGH] CWE-732 CVE-2018-1000071: roundcube version 1.3.4 and earlier contains an Insecure Permissions vulnerability in enigma plugin roundcube version 1.3.4 and earlier contains an Insecure Permissions vulnerability in enigma plugin that can result in exfiltration of gpg private key. This attack appear to be exploitable via network connectivity.
nvd
CVE-2017-16651HIGHCVSS 7.8KEVPoC≤ 1.1.9v1.2.0+9 more2017-11-09
CVE-2017-16651 [HIGH] CWE-552 CVE-2017-16651: Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized acce Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's filesystem, including configuration files, as exploited in the wild in November 2017. The attacker must be able to authenticate at the target system with a valid username/password as the attack requires an active sess
nvd
CVE-2015-5383HIGHCVSS 7.5v1.12017-05-23
CVE-2015-5383 [HIGH] CWE-200 CVE-2015-5383: Roundcube Webmail 1.1.x before 1.1.2 allows remote attackers to obtain sensitive information by read Roundcube Webmail 1.1.x before 1.1.2 allows remote attackers to obtain sensitive information by reading files in the (1) config, (2) temp, or (3) logs directory.
nvd
CVE-2015-5381MEDIUMCVSS 6.1v1.12017-05-23
CVE-2015-5381 [MEDIUM] CWE-79 CVE-2015-5381: Cross-site scripting (XSS) vulnerability in program/include/rcmail.php in Roundcube Webmail 1.1.x be Cross-site scripting (XSS) vulnerability in program/include/rcmail.php in Roundcube Webmail 1.1.x before 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the _mbox parameter to the default URI.
nvd
CVE-2015-5382MEDIUMCVSS 6.5v1.12017-05-23
CVE-2015-5382 [MEDIUM] CWE-200 CVE-2015-5382: program/steps/addressbook/photo.inc in Roundcube Webmail before 1.0.6 and 1.1.x before 1.1.2 allows program/steps/addressbook/photo.inc in Roundcube Webmail before 1.0.6 and 1.1.x before 1.1.2 allows remote authenticated users to read arbitrary files via the _alt parameter when uploading a vCard.
nvd
CVE-2017-8114HIGHCVSS 8.8fixed in 1.0.11≥ 1.1.0, < 1.1.9+1 more2017-04-29
CVE-2017-8114 [HIGH] CWE-269 CVE-2017-8114: Roundcube Webmail allows arbitrary password resets by authenticated users. This affects versions bef Roundcube Webmail allows arbitrary password resets by authenticated users. This affects versions before 1.0.11, 1.1.x before 1.1.9, and 1.2.x before 1.2.5. The problem is caused by an improperly restricted exec call in the virtualmin and sasl drivers of the password plugin.
nvd
CVE-2015-8864MEDIUMCVSS 6.1≤ 1.0.8v1.1+1 more2017-04-13
CVE-2015-8864 [MEDIUM] CWE-79 CVE-2015-8864: Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.0.9 and 1.1.x before 1.1.5 al Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.0.9 and 1.1.x before 1.1.5 allows remote attackers to inject arbitrary web script or HTML via a crafted SVG, a different vulnerability than CVE-2016-4068.
nvd
CVE-2016-4068MEDIUMCVSS 6.1≤ 1.0.8v1.1+1 more2017-04-13
CVE-2016-4068 [MEDIUM] CVE-2016-4068: Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.0.9 and 1.1.x before 1.1.5 al Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.0.9 and 1.1.x before 1.1.5 allows remote attackers to inject arbitrary web script or HTML via a crafted SVG, a different vulnerability than CVE-2015-8864.
nvd
CVE-2017-6820MEDIUMCVSS 6.1≤ 1.1.7v1.2.0+3 more2017-03-12
CVE-2017-6820 [MEDIUM] CWE-79 CVE-2017-6820: rcube_utils.php in Roundcube before 1.1.8 and 1.2.x before 1.2.4 is susceptible to a cross-site scri rcube_utils.php in Roundcube before 1.1.8 and 1.2.x before 1.2.4 is susceptible to a cross-site scripting vulnerability via a crafted Cascading Style Sheets (CSS) token sequence within an SVG element.
nvd
CVE-2015-2180HIGHCVSS 8.8≤ 1.12017-01-30
CVE-2015-2180 [HIGH] CWE-74 CVE-2015-2180: The DBMail driver in the Password plugin in Roundcube before 1.1.0 allows remote attackers to execut The DBMail driver in the Password plugin in Roundcube before 1.1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the password.
nvd
CVE-2015-2181HIGHCVSS 8.8fixed in 1.1.02017-01-30
CVE-2015-2181 [HIGH] CWE-119 CVE-2015-2181: Multiple buffer overflows in the DBMail driver in the Password plugin in Roundcube before 1.1.0 allo Multiple buffer overflows in the DBMail driver in the Password plugin in Roundcube before 1.1.0 allow remote attackers to have unspecified impact via the (1) password or (2) username.
nvd
CVE-2016-4552MEDIUMCVSS 6.1v1.22016-12-20
CVE-2016-4552 [MEDIUM] CWE-79 CVE-2016-4552: Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.2.0 allows remote attackers t Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.2.0 allows remote attackers to inject arbitrary web script or HTML via the href attribute in an area tag in an e-mail message.
nvd
CVE-2016-9920HIGHCVSS 7.5≤ 1.1.6v1.2.0+2 more2016-12-08
CVE-2016-9920 [HIGH] CWE-284 CVE-2016-9920: steps/mail/sendmail.inc in Roundcube before 1.1.7 and 1.2.x before 1.2.3, when no SMTP server is con steps/mail/sendmail.inc in Roundcube before 1.1.7 and 1.2.x before 1.2.3, when no SMTP server is configured and the sendmail program is enabled, does not properly restrict the use of custom envelope-from addresses on the sendmail command line, which allows remote authenticated users to execute arbitrary code via a modified HTTP request that sends a craf
nvd
CVE-2016-4069HIGHCVSS 8.8≤ 1.1.42016-08-25
CVE-2016-4069 [HIGH] CWE-352 CVE-2016-4069: Cross-site request forgery (CSRF) vulnerability in Roundcube Webmail before 1.1.5 allows remote atta Cross-site request forgery (CSRF) vulnerability in Roundcube Webmail before 1.1.5 allows remote attackers to hijack the authentication of users for requests that download attachments and cause a denial of service (disk consumption) via unspecified vectors.
nvd
CVE-2015-8793MEDIUMCVSS 6.1≤ 1.0.5v1.1.0+1 more2016-01-29
CVE-2015-8793 [MEDIUM] CVE-2015-8793: Cross-site scripting (XSS) vulnerability in program/include/rcmail.php in Roundcube before 1.0.6 and Cross-site scripting (XSS) vulnerability in program/include/rcmail.php in Roundcube before 1.0.6 and 1.1.x before 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the _mbox parameter in a mail task to the default URL, a different vulnerability than CVE-2011-2937.
nvd
CVE-2015-8105LOWCVSS 3.5≤ 1.0.6v1.1.0+2 more2015-11-10
CVE-2015-8105 [LOW] CWE-79 CVE-2015-8105: Cross-site scripting (XSS) vulnerability in program/js/app.js in Roundcube webmail before 1.0.7 and Cross-site scripting (XSS) vulnerability in program/js/app.js in Roundcube webmail before 1.0.7 and 1.1.x before 1.1.3 allows remote authenticated users to inject arbitrary web script or HTML via the file name in a drag-n-drop file upload.
nvd
CVE-2015-1433MEDIUMCVSS 4.3≤ 1.0.42015-02-03
CVE-2015-1433 [MEDIUM] CWE-79 CVE-2015-1433: program/lib/Roundcube/rcube_washtml.php in Roundcube before 1.0.5 does not properly quote strings, w program/lib/Roundcube/rcube_washtml.php in Roundcube before 1.0.5 does not properly quote strings, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the style attribute in an email.
nvd
CVE-2014-9587MEDIUMCVSS 6.8≤ 1.0.32015-01-15
CVE-2014-9587 [MEDIUM] CWE-352 CVE-2014-9587: Multiple cross-site request forgery (CSRF) vulnerabilities in Roundcube Webmail before 1.0.4 allow r Multiple cross-site request forgery (CSRF) vulnerabilities in Roundcube Webmail before 1.0.4 allow remote attackers to hijack the authentication of unspecified victims via unknown vectors, related to (1) address book operations or the (2) ACL or (3) Managesieve plugins.
nvd
Roundcube Webmail vulnerabilities | cvebase