cbcvebase.

Roundcube Webmail vulnerabilities

104 known vulnerabilities affecting roundcube/webmail.

Total CVEs
104
CISA KEV
11
actively exploited
Public exploits
12
Exploited in wild
12
Severity breakdown
CRITICAL11HIGH24MEDIUM62LOW7

Vulnerabilities

Page 5 of 6
CVE-2020-18670P4MEDIUMCVSS 5.4v1.4.42021-06-24
CVE-2020-18670 [MEDIUM] CWE-79 CVE-2020-18670: Cross Site Scripting (XSS) vulneraibility in Roundcube mail .4.4 via database host and user in /inst Cross Site Scripting (XSS) vulneraibility in Roundcube mail .4.4 via database host and user in /installer/test.php.
nvd
CVE-2015-8793P4MEDIUMCVSS 6.1≤ 1.0.5v1.1.0+1 more2016-01-29
CVE-2015-8793 [MEDIUM] CVE-2015-8793: Cross-site scripting (XSS) vulnerability in program/include/rcmail.php in Roundcube before 1.0.6 and Cross-site scripting (XSS) vulnerability in program/include/rcmail.php in Roundcube before 1.0.6 and 1.1.x before 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the _mbox parameter in a mail task to the default URL, a different vulnerability than CVE-2011-2937.
nvd
CVE-2016-4552P4MEDIUMCVSS 6.1v1.22016-12-20
CVE-2016-4552 [MEDIUM] CWE-79 CVE-2016-4552: Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.2.0 allows remote attackers t Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.2.0 allows remote attackers to inject arbitrary web script or HTML via the href attribute in an area tag in an e-mail message.
nvd
CVE-2017-6820P4MEDIUMCVSS 6.1≤ 1.1.7v1.2.0+3 more2017-03-12
CVE-2017-6820 [MEDIUM] CWE-79 CVE-2017-6820: rcube_utils.php in Roundcube before 1.1.8 and 1.2.x before 1.2.4 is susceptible to a cross-site scri rcube_utils.php in Roundcube before 1.1.8 and 1.2.x before 1.2.4 is susceptible to a cross-site scripting vulnerability via a crafted Cascading Style Sheets (CSS) token sequence within an SVG element.
nvd
CVE-2010-0464P4MEDIUMCVSS 5.0≤ 0.3.1v0.1+5 more2010-01-29
CVE-2010-0464 [MEDIUM] CWE-200 CVE-2010-0464: Roundcube 0.3.1 and earlier does not request that the web browser avoid DNS prefetching of domain na Roundcube 0.3.1 and earlier does not request that the web browser avoid DNS prefetching of domain names contained in e-mail messages, which makes it easier for remote attackers to determine the network location of the webmail user by logging DNS requests.
nvd
CVE-2020-18671P4MEDIUMCVSS 5.4≤ 1.4.42021-06-24
CVE-2020-18671 [MEDIUM] CWE-79 CVE-2020-18671: Cross Site Scripting (XSS) vulnerability in Roundcube Mail <=1.4.4 via smtp config in /installer/tes Cross Site Scripting (XSS) vulnerability in Roundcube Mail <=1.4.4 via smtp config in /installer/test.php.
nvd
CVE-2026-75004P4MEDIUMCVSS 4.3≥ 1.6.0, < 1.6.18≥ 1.7.0, < 1.7.32026-08-17
CVE-2026-75004 [MEDIUM] CWE-77 CVE-2026-75004: In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper rule name quoting could lead to In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper rule name quoting could lead to managesieve_disabled_actions setting bypass via a crafted rule name in a Sieve script. This issue only affects Roundcube instances using the managesieve plugin.
nvd
CVE-2026-35541P4MEDIUMCVSS 4.2fixed in 1.5.14≥ 1.6.0, < 1.6.142026-04-03
CVE-2026-35541 [MEDIUM] CWE-843 CVE-2026-35541: An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Incorrect password comparison An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Incorrect password comparison in the password plugin could lead to type confusion that allows a password change without knowing the old password.
nvd
CVE-2026-54432P4MEDIUMCVSS 4.7≥ 1.6.0, < 1.6.17≥ 1.7.0, < 1.7.22026-07-14
CVE-2026-54432 [MEDIUM] CWE-79 CVE-2026-54432: Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2 allows Stored Cross-Site Scripting (XSS). The Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2 allows Stored Cross-Site Scripting (XSS). The issue occurs because the attachment MIME type is not properly escaped on the attachment-validation warning page.
nvd
CVE-2026-25916P4MEDIUMCVSS 4.3fixed in 1.5.13≥ 1.6.0, < 1.6.132026-02-09
CVE-2026-25916 [MEDIUM] CWE-420 CVE-2026-25916: Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13, when "Block remote images" is used, does not Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13, when "Block remote images" is used, does not block SVG feImage.
nvd
CVE-2026-48849P4MEDIUMCVSS 4.4≥ 1.6.0, < 1.6.16≥ 1.7.0, < 1.7.12026-05-25
CVE-2026-48849 [MEDIUM] CWE-79 CVE-2026-48849: In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, an unsanitized subject field in the In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, an unsanitized subject field in the draft restored value could lead to stored XSS/HTML/CSS injection on shared mailboxes.
cvelistv5nvd
CVE-2026-48847P4LOWCVSS 3.7≥ 1.6.0, < 1.6.16≥ 1.7.0, < 1.7.12026-05-25
CVE-2026-48847 [LOW] CWE-669 CVE-2026-48847: Roundcube Webmail 1.6.x before 1.6.16, and 1.7.x before 1.7.1 allows pre-authentication arbitrary fi Roundcube Webmail 1.6.x before 1.6.16, and 1.7.x before 1.7.1 allows pre-authentication arbitrary file deletion via redis/memcache session poisoning bypass.
cvelistv5nvd
CVE-2015-1433P4MEDIUMCVSS 4.3≤ 1.0.42015-02-03
CVE-2015-1433 [MEDIUM] CWE-79 CVE-2015-1433: program/lib/Roundcube/rcube_washtml.php in Roundcube before 1.0.5 does not properly quote strings, w program/lib/Roundcube/rcube_washtml.php in Roundcube before 1.0.5 does not properly quote strings, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the style attribute in an email.
nvd
CVE-2013-5645P4MEDIUMCVSS 4.3≤ 0.9.2v0.1+29 more2013-08-29
CVE-2013-5645 [MEDIUM] CWE-79 CVE-2013-5645: Multiple cross-site scripting (XSS) vulnerabilities in Roundcube webmail before 0.9.3 allow user-ass Multiple cross-site scripting (XSS) vulnerabilities in Roundcube webmail before 0.9.3 allow user-assisted remote attackers to inject arbitrary web script or HTML via the body of a message visited in (1) new or (2) draft mode, related to compose.inc; and (3) might allow remote authenticated users to inject arbitrary web script or HTML via an HTML signat
nvd
CVE-2019-10740P4MEDIUMCVSS 4.3fixed in 1.3.102019-04-07
CVE-2019-10740 [MEDIUM] CWE-319 CVE-2019-10740: In Roundcube Webmail before 1.3.10, an attacker in possession of S/MIME or PGP encrypted emails can In Roundcube Webmail before 1.3.10, an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub-parts within a crafted multipart email. The encrypted part(s) can further be hidden using HTML/CSS or ASCII newline characters. This modified multipart email can be re-sent by the attacker to the intended receiver. If the receiver repl
nvd
CVE-2011-2937P4MEDIUMCVSS 4.3≤ 0.5.3v0.1+11 more2011-09-21
CVE-2011-2937 [MEDIUM] CWE-79 CVE-2011-2937: Cross-site scripting (XSS) vulnerability in the UI messages functionality in Roundcube Webmail befor Cross-site scripting (XSS) vulnerability in the UI messages functionality in Roundcube Webmail before 0.5.4 allows remote attackers to inject arbitrary web script or HTML via the _mbox parameter to the default URI.
nvd
CVE-2012-6121P4MEDIUMCVSS 4.3≤ 0.8.4v0.1+23 more2013-02-24
CVE-2012-6121 [MEDIUM] CWE-79 CVE-2012-6121: Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 0.8.5 allows remote attackers t Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 0.8.5 allows remote attackers to inject arbitrary web script or HTML via a (1) data:text or (2) vbscript link.
nvd
CVE-2009-0413P4MEDIUMCVSS 4.3v0.22009-02-03
CVE-2009-0413 [MEDIUM] CWE-79 CVE-2009-0413: Cross-site scripting (XSS) vulnerability in RoundCube Webmail (roundcubemail) 0.2 stable allows remo Cross-site scripting (XSS) vulnerability in RoundCube Webmail (roundcubemail) 0.2 stable allows remote attackers to inject arbitrary web script or HTML via the background attribute embedded in an HTML e-mail message.
nvd
CVE-2015-8105P4LOWCVSS 3.5≤ 1.0.6v1.1.0+2 more2015-11-10
CVE-2015-8105 [LOW] CWE-79 CVE-2015-8105: Cross-site scripting (XSS) vulnerability in program/js/app.js in Roundcube webmail before 1.0.7 and Cross-site scripting (XSS) vulnerability in program/js/app.js in Roundcube webmail before 1.0.7 and 1.1.x before 1.1.3 allows remote authenticated users to inject arbitrary web script or HTML via the file name in a drag-n-drop file upload.
nvd
CVE-2026-35538P4LOWCVSS 3.1fixed in 1.5.14≥ 1.6.0, < 1.6.142026-04-03
CVE-2026-35538 [LOW] CWE-88 CVE-2026-35538: An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsanitized IMAP SEARCH comma An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsanitized IMAP SEARCH command arguments could lead to IMAP injection or CSRF bypass during mail search.
nvd
Roundcube Webmail vulnerabilities | cvebase