cbcvebase.

Roundcube Webmail vulnerabilities

104 known vulnerabilities affecting roundcube/webmail.

Total CVEs
104
CISA KEV
11
actively exploited
Public exploits
12
Exploited in wild
12
Severity breakdown
CRITICAL11HIGH24MEDIUM62LOW7

Vulnerabilities

Page 3 of 6
CVE-2018-1000071P3HIGHCVSS 7.5≤ 1.3.42018-03-13
CVE-2018-1000071 [HIGH] CWE-732 CVE-2018-1000071: roundcube version 1.3.4 and earlier contains an Insecure Permissions vulnerability in enigma plugin roundcube version 1.3.4 and earlier contains an Insecure Permissions vulnerability in enigma plugin that can result in exfiltration of gpg private key. This attack appear to be exploitable via network connectivity.
nvd
CVE-2026-48843P3MEDIUMCVSS 6.5≥ 1.6.14, < 1.6.16≥ 1.7.0, < 1.7.12026-05-25
CVE-2026-48843 [MEDIUM] CWE-918 CVE-2026-48843: Roundcube Webmail 1 Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16,and 1.7.x before 1.7.1 has Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. The issue stems from an insufficient fix for CVE-2026-35540.
cvelistv5
CVE-2007-6321P4MEDIUMCVSS 4.3PoC≤ 0.12007-12-12
CVE-2007-6321 [MEDIUM] CWE-79 CVE-2007-6321: Cross-site scripting (XSS) vulnerability in RoundCube webmail 0.1rc2, 2007-12-09, and earlier versio Cross-site scripting (XSS) vulnerability in RoundCube webmail 0.1rc2, 2007-12-09, and earlier versions, when using Internet Explorer, allows remote attackers to inject arbitrary web script or HTML via style sheets containing expression commands.
nvd
CVE-2024-57004P4MEDIUMCVSS 6.1v1.6.92025-02-03
CVE-2024-57004 [MEDIUM] CWE-80 CVE-2024-57004: Cross-Site Scripting (XSS) vulnerability in Roundcube Webmail 1.6.9 allows remote authenticated user Cross-Site Scripting (XSS) vulnerability in Roundcube Webmail 1.6.9 allows remote authenticated users to upload a malicious file as an email attachment, leading to the triggering of the XSS by visiting the SENT session.
nvd
CVE-2018-19205P3HIGHCVSS 7.5fixed in 1.3.72018-11-12
CVE-2018-19205 [HIGH] CVE-2018-19205: Roundcube before 1.3.7 mishandles GnuPG MDC integrity-protection warnings, which makes it easier for Roundcube before 1.3.7 mishandles GnuPG MDC integrity-protection warnings, which makes it easier for attackers to obtain sensitive information, a related issue to CVE-2017-17688. This is associated with plugins/enigma/lib/enigma_driver_gnupg.php.
nvd
CVE-2015-5382P3MEDIUMCVSS 6.5v1.12017-05-23
CVE-2015-5382 [MEDIUM] CWE-200 CVE-2015-5382: program/steps/addressbook/photo.inc in Roundcube Webmail before 1.0.6 and 1.1.x before 1.1.2 allows program/steps/addressbook/photo.inc in Roundcube Webmail before 1.0.6 and 1.1.x before 1.1.2 allows remote authenticated users to read arbitrary files via the _alt parameter when uploading a vCard.
nvd
CVE-2026-74998P3HIGHCVSS 7.2≥ 1.6.0, < 1.6.18≥ 1.7.0, < 1.7.32026-08-17
CVE-2026-74998 [HIGH] CWE-79 CVE-2026-74998: In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, responses from the CSS (Cascading Style S In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, responses from the CSS (Cascading Style Sheets) proxy were not validated, which may result in information disclosure or XSS (cross-site scripting) via MIME sniffing.
nvd
CVE-2026-48846P3MEDIUMCVSS 6.5≥ 1.6.0, < 1.6.16≥ 1.7.0, < 1.7.12026-05-25
CVE-2026-48846 [MEDIUM] CWE-669 CVE-2026-48846: In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, the remote image blocking feature c In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, the remote image blocking feature can be bypassed via a crafted CSS var() value in an e-mail message, which may lead to information disclosure or access-control bypass.
cvelistv5nvd
CVE-2026-48845P3MEDIUMCVSS 6.5≥ 1.6.14, < 1.6.16≥ 1.7.0, < 1.7.12026-05-25
CVE-2026-48845 [MEDIUM] CWE-669 CVE-2026-48845: In Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16 and 1.7.x before 1.7.1, remote image blocking w In Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16 and 1.7.x before 1.7.1, remote image blocking was not honored for URLs pointing to local/private destinations, which may lead to information disclosure or privilege escalation via a text/html email message.
cvelistv5nvd
CVE-2026-35540P4MEDIUMCVSS 6.5≥ 1.6.0, < 1.6.14≥ 1.6.0, < 1.6.18+1 more2026-04-03
CVE-2026-35540 [MEDIUM] CWE-669 CVE-2026-35540: An issue was discovered in Roundcube Webmail 1.6.0 before 1.6.14. Insufficient Cascading Style Sheet An issue was discovered in Roundcube Webmail 1.6.0 before 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts.
nvd
CVE-2026-75000P4MEDIUMCVSS 5.8≥ 1.6.0, < 1.6.18≥ 1.7.0, < 1.7.32026-08-17
CVE-2026-75000 [MEDIUM] CWE-669 CVE-2026-75000: In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper HTML/CSS sanitization of the SVG In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper HTML/CSS sanitization of the SVG animate "by" attribute may lead to remote image blocking bypass, which in turn may lead to information disclosure or privilege escalation.
nvd
CVE-2019-15237P4HIGHCVSS 7.4≤ 1.3.92019-08-20
CVE-2019-15237 [HIGH] CVE-2019-15237: Roundcube Webmail through 1.3.9 mishandles Punycode xn-- domain names, leading to homograph attacks. Roundcube Webmail through 1.3.9 mishandles Punycode xn-- domain names, leading to homograph attacks.
nvd
CVE-2026-75006P4MEDIUMCVSS 5.8≥ 1.6.0, < 1.6.18≥ 1.7.0, < 1.7.32026-08-17
CVE-2026-75006 [MEDIUM] CVE-2026-75006: In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, insufficient Cascading Style Sheets (CSS) In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. This issue exists because of insufficient fixes for CVE-2026-35540, CVE-2026-48843 and CVE-2026-62643.
nvd
CVE-2014-9587P4MEDIUMCVSS 6.8≤ 1.0.32015-01-15
CVE-2014-9587 [MEDIUM] CWE-352 CVE-2014-9587: Multiple cross-site request forgery (CSRF) vulnerabilities in Roundcube Webmail before 1.0.4 allow r Multiple cross-site request forgery (CSRF) vulnerabilities in Roundcube Webmail before 1.0.4 allow remote attackers to hijack the authentication of unspecified victims via unknown vectors, related to (1) address book operations or the (2) ACL or (3) Managesieve plugins.
nvd
CVE-2026-62642P4MEDIUMCVSS 6.5≥ 1.6.0, < 1.6.17≥ 1.7.0, < 1.7.22026-07-14
CVE-2026-62642 [MEDIUM] CWE-835 CVE-2026-62642: In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, an infinite loop was discovered in the TN In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, an infinite loop was discovered in the TNEF decoder, which may lead to denial of service upon opening an email with a TNEF attachment.
nvd
CVE-2008-5620P4HIGHCVSS 7.8≤ 0.2v0.1+2 more2008-12-17
CVE-2008-5620 [HIGH] CWE-399 CVE-2008-5620: RoundCube Webmail (roundcubemail) before 0.2-beta allows remote attackers to cause a denial of servi RoundCube Webmail (roundcubemail) before 0.2-beta allows remote attackers to cause a denial of service (memory consumption) via crafted size parameters that are used to create a large quota image.
nvd
CVE-2011-1492P4MEDIUMCVSS 5.5≤ 0.5v0.1+9 more2011-04-08
CVE-2011-1492 [MEDIUM] CWE-20 CVE-2011-1492: steps/utils/modcss.inc in Roundcube Webmail before 0.5.1 does not properly verify that a request is steps/utils/modcss.inc in Roundcube Webmail before 0.5.1 does not properly verify that a request is an expected request for an external Cascading Style Sheets (CSS) stylesheet, which allows remote authenticated users to trigger arbitrary outbound TCP connections from the server, and possibly obtain sensitive information, via a crafted request.
nvd
CVE-2026-35542P4MEDIUMCVSS 5.3fixed in 1.5.14≥ 1.6.0, < 1.6.142026-04-03
CVE-2026-35542 [MEDIUM] CWE-669 CVE-2026-35542: An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking fea An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via a crafted background attribute of a BODY element in an e-mail message. This may lead to information disclosure or access-control bypass.
nvd
CVE-2026-35543P4MEDIUMCVSS 5.3fixed in 1.5.14≥ 1.6.0, < 1.6.142026-04-03
CVE-2026-35543 [MEDIUM] CWE-669 CVE-2026-35543: An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking fea An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via SVG content (with animate attributes) in an e-mail message. This may lead to information disclosure or access-control bypass.
nvd
CVE-2020-12626P4MEDIUMCVSS 6.5fixed in 1.4.42020-05-04
CVE-2020-12626 [MEDIUM] CWE-352 CVE-2020-12626: An issue was discovered in Roundcube Webmail before 1.4.4. A CSRF attack can cause an authenticated An issue was discovered in Roundcube Webmail before 1.4.4. A CSRF attack can cause an authenticated user to be logged out because POST was not considered.
nvd
Roundcube Webmail vulnerabilities | cvebase