Roundcube records
99 published records for vendor roundcube.
Researcher profile
- Entered KEV
- 11 · 11.1%
- Weaponized
- 11 · 11.1%
- Pre-auth RCE
- 4
- With a fix record
- 93.9%
- Median publish → KEV
- 308 days
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')42
- CWE-669 Incorrect Resource Transfer Between Spheres8
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor6
- CWE-352 Cross-Site Request Forgery (CSRF)5
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')4
The weakness classes this vendor ships most often: where to look.
CWEBug bounty scope
The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.
All records
99 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
95Now | CVE-2025-49113Weaponized | Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in aroundcube · webmail · CWE-502 | High8.8 | KEV | 98.9% | Jun 2, 2025 |
94Now | CVE-2020-12641Weaponized | rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setroundcube · webmail · CWE-78 | Critical9.8 | KEV | 84.3% | May 4, 2020 |
92Now | CVE-2024-42009Weaponized | A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails ofroundcube · webmail · CWE-79 | Critical9.3 | KEV | 82.9% | Aug 5, 2024 |
90Now | CVE-2021-44026Weaponized | Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.roundcube · webmail · CWE-89 | Critical9.8 | KEV | 69.9% | Nov 19, 2021 |
77This week | CVE-2020-13965Weaponized | An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5.roundcube · webmail · CWE-79 | Medium6.1 | KEV | 76.6% | Jun 8, 2020 |
76This week | CVE-2024-37383Weaponized | Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.roundcube · webmail · CWE-79 | Medium6.1 | KEV | 73.3% | Jun 7, 2024 |
75This week | CVE-2017-16651Weaponized | Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's fileroundcube · webmail · CWE-552 | High7.8 | KEV | 45.7% | Nov 9, 2017 |
74This week | CVE-2023-5631Weaponized | Stored XSS vulnerability in Roundcuberoundcube · webmail · CWE-79 | Medium5.4 | KEV | 75.9% | Oct 18, 2023 |
73This week | CVE-2023-43770Weaponized | Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of roundcube · webmail · CWE-79 | Medium6.1 | KEV | 63.7% | Sep 22, 2023 |
64This week | CVE-2020-35730Weaponized | An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10.roundcube · webmail · CWE-79 | Medium6.1 | KEV | 32.7% | Dec 28, 2020 |
62This week | CVE-2025-68461Weaponized | Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG droundcube · webmail · CWE-79 | Medium6.1 | KEV | 26.8% | Dec 18, 2025 |
58Plan | CVE-2008-5619Proof of concept | html2text.php in Chuggnutt HTML to Text Converter, as used in PHPMailer before 5.2.10, RoundCube Webmail (roundcubemail) 0.2-1.alpha and 0.2roundcube · webmail · CWE-94 | Critical10.0 | — | 58.6% | Dec 16, 2008 |
50Plan | CVE-2024-42010No exploit | mod_css_styles in Roundcube through 1.5.7 and 1.6.x through 1.6.7 insufficiently filters Cascading Style Sheets (CSS) token sequences in renCWE-200 | High7.5 | — | 66.7% | Aug 5, 2024 |
47Plan | CVE-2024-42008Proof of concept | A Cross-Site Scripting vulnerability in rcmail_action_mail_get->run() in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attroundcube · webmail · CWE-79 | Critical9.3 | — | 34.2% | Aug 5, 2024 |
41Plan | CVE-2018-19206No exploit | steps/mail/func.inc in Roundcube before 1.3.8 has XSS via crafted use of <svg><style>, as demonstrated by an onload attribute in a BODY elemroundcube · webmail · CWE-79 | Medium6.1 | — | 55.9% | Nov 12, 2018 |
41Plan | CVE-2020-12640Proof of concept | Roundcube Webmail before 1.4.4 allows attackers to include local files and execute code via directory traversal in a plugin name to rcube_plroundcube · webmail · CWE-22 | Critical9.8 | — | 6.7% | May 4, 2020 |
40Plan | CVE-2026-62643No exploit | In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages maroundcube · webmail · CWE-918 | Critical10.0 | — | 0.4% | Jul 14, 2026 |
40Plan | CVE-2026-54433Proof of concept | In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafted plain-text email messageroundcube · webmail · CWE-79 | Critical10.0 | — | 0.3% | Jul 14, 2026 |
39Monitor | CVE-2024-37385No exploit | Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 on Windows allows command injection via im_convert_path and im_identify_path.roundcube · webmail · CWE-77 | Critical9.8 | — | 1.5% | Jun 7, 2024 |
39Monitor | CVE-2026-75003No exploit | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed url() in a FuncIRI attribute of an SVG image could evade the remote iroundcube · webmail · CWE-669 | Critical9.8 | — | 0.6% | Aug 17, 2026 |
39Monitor | CVE-2026-62644No exploit | In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing viaroundcube · webmail · CWE-290 | Critical9.8 | — | 0.5% | Jul 14, 2026 |
37Monitor | CVE-2015-8770Proof of concept | Directory traversal vulnerability in the set_skin function in program/include/rcmail_output_html.php in Roundcube before 1.0.8 and 1.1.x befroundcube · roundcube webmail · CWE-22 | High7.5 | — | 22.4% | Jan 29, 2016 |
36Monitor | CVE-2015-2180No exploit | The DBMail driver in the Password plugin in Roundcube before 1.1.0 allows remote attackers to execute arbitrary commands via shell metachararoundcube · webmail · CWE-74 | High8.8 | — | 4.7% | Jan 30, 2017 |
36Monitor | CVE-2017-8114No exploit | Roundcube Webmail allows arbitrary password resets by authenticated users.roundcube · webmail · CWE-269 | High8.8 | — | 3.5% | Apr 29, 2017 |
36Monitor | CVE-2015-2181No exploit | Multiple buffer overflows in the DBMail driver in the Password plugin in Roundcube before 1.1.0 allow remote attackers to have unspecified iroundcube · webmail · CWE-119 | High8.8 | — | 2.9% | Jan 30, 2017 |
- CVE-2025-4911395Now
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a
HighCVSS 8.8KEVWeaponizedEPSS 99%roundcube · webmailJun 2, 2025
- CVE-2020-1264194Now
rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration set
CriticalCVSS 9.8KEVWeaponizedEPSS 84%roundcube · webmailMay 4, 2020
- CVE-2024-4200992Now
A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of
CriticalCVSS 9.3KEVWeaponizedEPSS 83%roundcube · webmailAug 5, 2024
- CVE-2021-4402690Now
Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.
CriticalCVSS 9.8KEVWeaponizedEPSS 70%roundcube · webmailNov 19, 2021
- CVE-2020-1396577This week
An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5.
MediumCVSS 6.1KEVWeaponizedEPSS 77%roundcube · webmailJun 8, 2020
- CVE-2024-3738376This week
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.
MediumCVSS 6.1KEVWeaponizedEPSS 73%roundcube · webmailJun 7, 2024
- CVE-2017-1665175This week
Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's file
HighCVSS 7.8KEVWeaponizedEPSS 46%roundcube · webmailNov 9, 2017
- CVE-2023-563174This week
Stored XSS vulnerability in Roundcube
MediumCVSS 5.4KEVWeaponizedEPSS 76%roundcube · webmailOct 18, 2023
- CVE-2023-4377073This week
Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of
MediumCVSS 6.1KEVWeaponizedEPSS 64%roundcube · webmailSep 22, 2023
- CVE-2020-3573064This week
An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10.
MediumCVSS 6.1KEVWeaponizedEPSS 33%roundcube · webmailDec 28, 2020
- CVE-2025-6846162This week
Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG d
MediumCVSS 6.1KEVWeaponizedEPSS 27%roundcube · webmailDec 18, 2025
- CVE-2008-561958Plan
html2text.php in Chuggnutt HTML to Text Converter, as used in PHPMailer before 5.2.10, RoundCube Webmail (roundcubemail) 0.2-1.alpha and 0.2
CriticalCVSS 10.0Proof of conceptEPSS 59%roundcube · webmailDec 16, 2008
- CVE-2024-4201050Plan
mod_css_styles in Roundcube through 1.5.7 and 1.6.x through 1.6.7 insufficiently filters Cascading Style Sheets (CSS) token sequences in ren
HighCVSS 7.5No exploitEPSS 67%Aug 5, 2024
- CVE-2024-4200847Plan
A Cross-Site Scripting vulnerability in rcmail_action_mail_get->run() in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote att
CriticalCVSS 9.3Proof of conceptEPSS 34%roundcube · webmailAug 5, 2024
- CVE-2018-1920641Plan
steps/mail/func.inc in Roundcube before 1.3.8 has XSS via crafted use of <svg><style>, as demonstrated by an onload attribute in a BODY elem
MediumCVSS 6.1No exploitEPSS 56%roundcube · webmailNov 12, 2018
- CVE-2020-1264041Plan
Roundcube Webmail before 1.4.4 allows attackers to include local files and execute code via directory traversal in a plugin name to rcube_pl
CriticalCVSS 9.8Proof of conceptEPSS 7%roundcube · webmailMay 4, 2020
- CVE-2026-6264340Plan
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages ma
CriticalCVSS 10.0No exploitEPSS 0%roundcube · webmailJul 14, 2026
- CVE-2026-5443340Plan
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafted plain-text email message
CriticalCVSS 10.0Proof of conceptEPSS 0%roundcube · webmailJul 14, 2026
- CVE-2024-3738539Monitor
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 on Windows allows command injection via im_convert_path and im_identify_path.
CriticalCVSS 9.8No exploitEPSS 1%roundcube · webmailJun 7, 2024
- CVE-2026-7500339Monitor
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed url() in a FuncIRI attribute of an SVG image could evade the remote i
CriticalCVSS 9.8No exploitEPSS 1%roundcube · webmailAug 17, 2026
- CVE-2026-6264439Monitor
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing via
CriticalCVSS 9.8No exploitEPSS 1%roundcube · webmailJul 14, 2026
- CVE-2015-877037Monitor
Directory traversal vulnerability in the set_skin function in program/include/rcmail_output_html.php in Roundcube before 1.0.8 and 1.1.x bef
HighCVSS 7.5Proof of conceptEPSS 22%roundcube · roundcube webmailJan 29, 2016
- CVE-2015-218036Monitor
The DBMail driver in the Password plugin in Roundcube before 1.1.0 allows remote attackers to execute arbitrary commands via shell metachara
HighCVSS 8.8No exploitEPSS 5%roundcube · webmailJan 30, 2017
- CVE-2017-811436Monitor
Roundcube Webmail allows arbitrary password resets by authenticated users.
HighCVSS 8.8No exploitEPSS 3%roundcube · webmailApr 29, 2017
- CVE-2015-218136Monitor
Multiple buffer overflows in the DBMail driver in the Password plugin in Roundcube before 1.1.0 allow remote attackers to have unspecified i
HighCVSS 8.8No exploitEPSS 3%roundcube · webmailJan 30, 2017