Skip to content
Noroxi

Roundcube records

99 published records for vendor roundcube.

Bug bounty scope

The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.

All records

99 records
  • Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a

    HighCVSS 8.8KEVWeaponizedEPSS 99%

    roundcube · webmailJun 2, 2025

  • rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration set

    CriticalCVSS 9.8KEVWeaponizedEPSS 84%

    roundcube · webmailMay 4, 2020

  • A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of

    CriticalCVSS 9.3KEVWeaponizedEPSS 83%

    roundcube · webmailAug 5, 2024

  • Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.

    CriticalCVSS 9.8KEVWeaponizedEPSS 70%

    roundcube · webmailNov 19, 2021

  • CVE-2020-13965
    77This week

    An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5.

    MediumCVSS 6.1KEVWeaponizedEPSS 77%

    roundcube · webmailJun 8, 2020

  • CVE-2024-37383
    76This week

    Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.

    MediumCVSS 6.1KEVWeaponizedEPSS 73%

    roundcube · webmailJun 7, 2024

  • CVE-2017-16651
    75This week

    Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's file

    HighCVSS 7.8KEVWeaponizedEPSS 46%

    roundcube · webmailNov 9, 2017

  • CVE-2023-5631
    74This week

    Stored XSS vulnerability in Roundcube

    MediumCVSS 5.4KEVWeaponizedEPSS 76%

    roundcube · webmailOct 18, 2023

  • CVE-2023-43770
    73This week

    Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of

    MediumCVSS 6.1KEVWeaponizedEPSS 64%

    roundcube · webmailSep 22, 2023

  • CVE-2020-35730
    64This week

    An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10.

    MediumCVSS 6.1KEVWeaponizedEPSS 33%

    roundcube · webmailDec 28, 2020

  • CVE-2025-68461
    62This week

    Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG d

    MediumCVSS 6.1KEVWeaponizedEPSS 27%

    roundcube · webmailDec 18, 2025

  • html2text.php in Chuggnutt HTML to Text Converter, as used in PHPMailer before 5.2.10, RoundCube Webmail (roundcubemail) 0.2-1.alpha and 0.2

    CriticalCVSS 10.0Proof of conceptEPSS 59%

    roundcube · webmailDec 16, 2008

  • mod_css_styles in Roundcube through 1.5.7 and 1.6.x through 1.6.7 insufficiently filters Cascading Style Sheets (CSS) token sequences in ren

    HighCVSS 7.5No exploitEPSS 67%

    Aug 5, 2024

  • A Cross-Site Scripting vulnerability in rcmail_action_mail_get->run() in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote att

    CriticalCVSS 9.3Proof of conceptEPSS 34%

    roundcube · webmailAug 5, 2024

  • steps/mail/func.inc in Roundcube before 1.3.8 has XSS via crafted use of <svg><style>, as demonstrated by an onload attribute in a BODY elem

    MediumCVSS 6.1No exploitEPSS 56%

    roundcube · webmailNov 12, 2018

  • Roundcube Webmail before 1.4.4 allows attackers to include local files and execute code via directory traversal in a plugin name to rcube_pl

    CriticalCVSS 9.8Proof of conceptEPSS 7%

    roundcube · webmailMay 4, 2020

  • In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages ma

    CriticalCVSS 10.0No exploitEPSS 0%

    roundcube · webmailJul 14, 2026

  • In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafted plain-text email message

    CriticalCVSS 10.0Proof of conceptEPSS 0%

    roundcube · webmailJul 14, 2026

  • Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 on Windows allows command injection via im_convert_path and im_identify_path.

    CriticalCVSS 9.8No exploitEPSS 1%

    roundcube · webmailJun 7, 2024

  • In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed url() in a FuncIRI attribute of an SVG image could evade the remote i

    CriticalCVSS 9.8No exploitEPSS 1%

    roundcube · webmailAug 17, 2026

  • In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing via

    CriticalCVSS 9.8No exploitEPSS 1%

    roundcube · webmailJul 14, 2026

  • CVE-2015-8770
    37Monitor

    Directory traversal vulnerability in the set_skin function in program/include/rcmail_output_html.php in Roundcube before 1.0.8 and 1.1.x bef

    HighCVSS 7.5Proof of conceptEPSS 22%

    roundcube · roundcube webmailJan 29, 2016

  • CVE-2015-2180
    36Monitor

    The DBMail driver in the Password plugin in Roundcube before 1.1.0 allows remote attackers to execute arbitrary commands via shell metachara

    HighCVSS 8.8No exploitEPSS 5%

    roundcube · webmailJan 30, 2017

  • CVE-2017-8114
    36Monitor

    Roundcube Webmail allows arbitrary password resets by authenticated users.

    HighCVSS 8.8No exploitEPSS 3%

    roundcube · webmailApr 29, 2017

  • CVE-2015-2181
    36Monitor

    Multiple buffer overflows in the DBMail driver in the Password plugin in Roundcube before 1.1.0 allow remote attackers to have unspecified i

    HighCVSS 8.8No exploitEPSS 3%

    roundcube · webmailJan 30, 2017