Перейти к содержимому
Noroxi

Записи Roundcube

99 опубликованных записей вендора roundcube.

Профиль для исследователя

Попали в KEV
11 · 11,1 %
С эксплойтом
11 · 11,1 %
Pre-auth RCE
4
С записью об исправлении
93,9 %
Медиана: публикация → KEV
308 дн.

Охват bug bounty

Вендор продукта присутствует в публичной программе. Сопоставление по имени; проверьте текст scope в программе.

Все записи

99 записей
  • CVE-2025-49113
    95Срочно

    Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a

    ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 99 %

    roundcube · webmail2 июн. 2025 г.

  • CVE-2020-12641
    94Срочно

    rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration set

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 84 %

    roundcube · webmail4 мая 2020 г.

  • CVE-2024-42009
    92Срочно

    A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of

    КритическаяCVSS 9,3KEVГотовый эксплойтEPSS 83 %

    roundcube · webmail5 авг. 2024 г.

  • CVE-2021-44026
    90Срочно

    Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 70 %

    roundcube · webmail19 нояб. 2021 г.

  • CVE-2020-13965
    77На этой неделе

    An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5.

    СредняяCVSS 6,1KEVГотовый эксплойтEPSS 77 %

    roundcube · webmail8 июн. 2020 г.

  • CVE-2024-37383
    76На этой неделе

    Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.

    СредняяCVSS 6,1KEVГотовый эксплойтEPSS 73 %

    roundcube · webmail7 июн. 2024 г.

  • CVE-2017-16651
    75На этой неделе

    Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's file

    ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 46 %

    roundcube · webmail9 нояб. 2017 г.

  • CVE-2023-5631
    74На этой неделе

    Stored XSS vulnerability in Roundcube

    СредняяCVSS 5,4KEVГотовый эксплойтEPSS 76 %

    roundcube · webmail18 окт. 2023 г.

  • CVE-2023-43770
    73На этой неделе

    Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of

    СредняяCVSS 6,1KEVГотовый эксплойтEPSS 64 %

    roundcube · webmail22 сент. 2023 г.

  • CVE-2020-35730
    64На этой неделе

    An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10.

    СредняяCVSS 6,1KEVГотовый эксплойтEPSS 33 %

    roundcube · webmail28 дек. 2020 г.

  • CVE-2025-68461
    62На этой неделе

    Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG d

    СредняяCVSS 6,1KEVГотовый эксплойтEPSS 27 %

    roundcube · webmail18 дек. 2025 г.

  • CVE-2008-5619
    58В плане

    html2text.php in Chuggnutt HTML to Text Converter, as used in PHPMailer before 5.2.10, RoundCube Webmail (roundcubemail) 0.2-1.alpha and 0.2

    КритическаяCVSS 10,0Proof of conceptEPSS 59 %

    roundcube · webmail16 дек. 2008 г.

  • CVE-2024-42010
    50В плане

    mod_css_styles in Roundcube through 1.5.7 and 1.6.x through 1.6.7 insufficiently filters Cascading Style Sheets (CSS) token sequences in ren

    ВысокаяCVSS 7,5Эксплойта нетEPSS 67 %

    5 авг. 2024 г.

  • CVE-2024-42008
    47В плане

    A Cross-Site Scripting vulnerability in rcmail_action_mail_get->run() in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote att

    КритическаяCVSS 9,3Proof of conceptEPSS 34 %

    roundcube · webmail5 авг. 2024 г.

  • CVE-2018-19206
    41В плане

    steps/mail/func.inc in Roundcube before 1.3.8 has XSS via crafted use of <svg><style>, as demonstrated by an onload attribute in a BODY elem

    СредняяCVSS 6,1Эксплойта нетEPSS 56 %

    roundcube · webmail12 нояб. 2018 г.

  • CVE-2020-12640
    41В плане

    Roundcube Webmail before 1.4.4 allows attackers to include local files and execute code via directory traversal in a plugin name to rcube_pl

    КритическаяCVSS 9,8Proof of conceptEPSS 7 %

    roundcube · webmail4 мая 2020 г.

  • CVE-2026-62643
    40В плане

    In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages ma

    КритическаяCVSS 10,0Эксплойта нетEPSS 0 %

    roundcube · webmail14 июл. 2026 г.

  • CVE-2026-54433
    40В плане

    In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafted plain-text email message

    КритическаяCVSS 10,0Proof of conceptEPSS 0 %

    roundcube · webmail14 июл. 2026 г.

  • CVE-2024-37385
    39Наблюдать

    Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 on Windows allows command injection via im_convert_path and im_identify_path.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    roundcube · webmail7 июн. 2024 г.

  • CVE-2026-75003
    39Наблюдать

    In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed url() in a FuncIRI attribute of an SVG image could evade the remote i

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    roundcube · webmail17 авг. 2026 г.

  • CVE-2026-62644
    39Наблюдать

    In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing via

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    roundcube · webmail14 июл. 2026 г.

  • CVE-2015-8770
    37Наблюдать

    Directory traversal vulnerability in the set_skin function in program/include/rcmail_output_html.php in Roundcube before 1.0.8 and 1.1.x bef

    ВысокаяCVSS 7,5Proof of conceptEPSS 22 %

    roundcube · roundcube webmail29 янв. 2016 г.

  • CVE-2015-2180
    36Наблюдать

    The DBMail driver in the Password plugin in Roundcube before 1.1.0 allows remote attackers to execute arbitrary commands via shell metachara

    ВысокаяCVSS 8,8Эксплойта нетEPSS 5 %

    roundcube · webmail30 янв. 2017 г.

  • CVE-2017-8114
    36Наблюдать

    Roundcube Webmail allows arbitrary password resets by authenticated users.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %

    roundcube · webmail29 апр. 2017 г.

  • CVE-2015-2181
    36Наблюдать

    Multiple buffer overflows in the DBMail driver in the Password plugin in Roundcube before 1.1.0 allow remote attackers to have unspecified i

    ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %

    roundcube · webmail30 янв. 2017 г.