cbcvebase.

Roundcube Webmail vulnerabilities

104 known vulnerabilities affecting roundcube/webmail.

Total CVEs
104
CISA KEV
11
actively exploited
Public exploits
12
Exploited in wild
12
Severity breakdown
CRITICAL11HIGH24MEDIUM62LOW7

Vulnerabilities

Page 6 of 6
CVE-2011-1491P4LOWCVSS 3.5≤ 0.5v0.1+9 more2011-04-08
CVE-2011-1491 [LOW] CWE-20 CVE-2011-1491: The login form in Roundcube Webmail before 0.5.1 does not properly handle a correctly authenticated The login form in Roundcube Webmail before 0.5.1 does not properly handle a correctly authenticated but unintended login attempt, which makes it easier for remote authenticated users to obtain sensitive information by arranging for a victim to login to the attacker's account and then compose an e-mail message, related to a "login CSRF" issue.
nvd
CVE-2013-5646P4LOWCVSS 3.5v1.02013-08-29
CVE-2013-5646 [LOW] CWE-79 CVE-2013-5646: Cross-site scripting (XSS) vulnerability in Roundcube webmail 1.0-git allows remote authenticated us Cross-site scripting (XSS) vulnerability in Roundcube webmail 1.0-git allows remote authenticated users to inject arbitrary web script or HTML via the Name field of an addressbook group.
nvd
CVE-2012-3507P4LOWCVSS 2.6≤ 0.7.3v0.1+18 more2012-08-25
CVE-2012-3507 [LOW] CWE-79 CVE-2012-3507: Cross-site scripting (XSS) vulnerability in program/steps/mail/func.inc in RoundCube Webmail before Cross-site scripting (XSS) vulnerability in program/steps/mail/func.inc in RoundCube Webmail before 0.8.0, when using the Larry skin, allows remote attackers to inject arbitrary web script or HTML via the email message subject.
nvd
CVE-2012-1253P4LOWCVSS 2.6≤ 0.6v0.1+14 more2012-06-04
CVE-2012-1253 [LOW] CWE-79 CVE-2012-1253: Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 0.7, when Internet Explorer is Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 0.7, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via vectors involving an embedded image attachment.
nvd
Roundcube Webmail vulnerabilities | cvebase