Записи Roundcube
99 опубликованных записей вендора roundcube.
Профиль для исследователя
- Попали в KEV
- 11 · 11,1 %
- С эксплойтом
- 11 · 11,1 %
- Pre-auth RCE
- 4
- С записью об исправлении
- 93,9 %
- Медиана: публикация → KEV
- 308 дн.
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')42
- CWE-669 Incorrect Resource Transfer Between Spheres8
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor6
- CWE-352 Cross-Site Request Forgery (CSRF)5
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')4
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEОхват bug bounty
Вендор продукта присутствует в публичной программе. Сопоставление по имени; проверьте текст scope в программе.
Все записи
99 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
95Срочно | CVE-2025-49113Готовый эксплойт | Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in aroundcube · webmail · CWE-502 | Высокая8,8 | KEV | 98,9 % | 2 июн. 2025 г. |
94Срочно | CVE-2020-12641Готовый эксплойт | rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setroundcube · webmail · CWE-78 | Критическая9,8 | KEV | 84,3 % | 4 мая 2020 г. |
92Срочно | CVE-2024-42009Готовый эксплойт | A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails ofroundcube · webmail · CWE-79 | Критическая9,3 | KEV | 82,9 % | 5 авг. 2024 г. |
90Срочно | CVE-2021-44026Готовый эксплойт | Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.roundcube · webmail · CWE-89 | Критическая9,8 | KEV | 69,9 % | 19 нояб. 2021 г. |
77На этой неделе | CVE-2020-13965Готовый эксплойт | An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5.roundcube · webmail · CWE-79 | Средняя6,1 | KEV | 76,6 % | 8 июн. 2020 г. |
76На этой неделе | CVE-2024-37383Готовый эксплойт | Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.roundcube · webmail · CWE-79 | Средняя6,1 | KEV | 73,3 % | 7 июн. 2024 г. |
75На этой неделе | CVE-2017-16651Готовый эксплойт | Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's fileroundcube · webmail · CWE-552 | Высокая7,8 | KEV | 45,7 % | 9 нояб. 2017 г. |
74На этой неделе | CVE-2023-5631Готовый эксплойт | Stored XSS vulnerability in Roundcuberoundcube · webmail · CWE-79 | Средняя5,4 | KEV | 75,9 % | 18 окт. 2023 г. |
73На этой неделе | CVE-2023-43770Готовый эксплойт | Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of roundcube · webmail · CWE-79 | Средняя6,1 | KEV | 63,7 % | 22 сент. 2023 г. |
64На этой неделе | CVE-2020-35730Готовый эксплойт | An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10.roundcube · webmail · CWE-79 | Средняя6,1 | KEV | 32,7 % | 28 дек. 2020 г. |
62На этой неделе | CVE-2025-68461Готовый эксплойт | Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG droundcube · webmail · CWE-79 | Средняя6,1 | KEV | 26,8 % | 18 дек. 2025 г. |
58В плане | CVE-2008-5619Proof of concept | html2text.php in Chuggnutt HTML to Text Converter, as used in PHPMailer before 5.2.10, RoundCube Webmail (roundcubemail) 0.2-1.alpha and 0.2roundcube · webmail · CWE-94 | Критическая10,0 | — | 58,6 % | 16 дек. 2008 г. |
50В плане | CVE-2024-42010Эксплойта нет | mod_css_styles in Roundcube through 1.5.7 and 1.6.x through 1.6.7 insufficiently filters Cascading Style Sheets (CSS) token sequences in renCWE-200 | Высокая7,5 | — | 66,7 % | 5 авг. 2024 г. |
47В плане | CVE-2024-42008Proof of concept | A Cross-Site Scripting vulnerability in rcmail_action_mail_get->run() in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attroundcube · webmail · CWE-79 | Критическая9,3 | — | 34,2 % | 5 авг. 2024 г. |
41В плане | CVE-2018-19206Эксплойта нет | steps/mail/func.inc in Roundcube before 1.3.8 has XSS via crafted use of <svg><style>, as demonstrated by an onload attribute in a BODY elemroundcube · webmail · CWE-79 | Средняя6,1 | — | 55,9 % | 12 нояб. 2018 г. |
41В плане | CVE-2020-12640Proof of concept | Roundcube Webmail before 1.4.4 allows attackers to include local files and execute code via directory traversal in a plugin name to rcube_plroundcube · webmail · CWE-22 | Критическая9,8 | — | 6,7 % | 4 мая 2020 г. |
40В плане | CVE-2026-62643Эксплойта нет | In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages maroundcube · webmail · CWE-918 | Критическая10,0 | — | 0,4 % | 14 июл. 2026 г. |
40В плане | CVE-2026-54433Proof of concept | In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafted plain-text email messageroundcube · webmail · CWE-79 | Критическая10,0 | — | 0,3 % | 14 июл. 2026 г. |
39Наблюдать | CVE-2024-37385Эксплойта нет | Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 on Windows allows command injection via im_convert_path and im_identify_path.roundcube · webmail · CWE-77 | Критическая9,8 | — | 1,5 % | 7 июн. 2024 г. |
39Наблюдать | CVE-2026-75003Эксплойта нет | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed url() in a FuncIRI attribute of an SVG image could evade the remote iroundcube · webmail · CWE-669 | Критическая9,8 | — | 0,6 % | 17 авг. 2026 г. |
39Наблюдать | CVE-2026-62644Эксплойта нет | In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing viaroundcube · webmail · CWE-290 | Критическая9,8 | — | 0,5 % | 14 июл. 2026 г. |
37Наблюдать | CVE-2015-8770Proof of concept | Directory traversal vulnerability in the set_skin function in program/include/rcmail_output_html.php in Roundcube before 1.0.8 and 1.1.x befroundcube · roundcube webmail · CWE-22 | Высокая7,5 | — | 22,4 % | 29 янв. 2016 г. |
36Наблюдать | CVE-2015-2180Эксплойта нет | The DBMail driver in the Password plugin in Roundcube before 1.1.0 allows remote attackers to execute arbitrary commands via shell metachararoundcube · webmail · CWE-74 | Высокая8,8 | — | 4,7 % | 30 янв. 2017 г. |
36Наблюдать | CVE-2017-8114Эксплойта нет | Roundcube Webmail allows arbitrary password resets by authenticated users.roundcube · webmail · CWE-269 | Высокая8,8 | — | 3,5 % | 29 апр. 2017 г. |
36Наблюдать | CVE-2015-2181Эксплойта нет | Multiple buffer overflows in the DBMail driver in the Password plugin in Roundcube before 1.1.0 allow remote attackers to have unspecified iroundcube · webmail · CWE-119 | Высокая8,8 | — | 2,9 % | 30 янв. 2017 г. |
- CVE-2025-4911395Срочно
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 99 %roundcube · webmail2 июн. 2025 г.
- CVE-2020-1264194Срочно
rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration set
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 84 %roundcube · webmail4 мая 2020 г.
- CVE-2024-4200992Срочно
A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of
КритическаяCVSS 9,3KEVГотовый эксплойтEPSS 83 %roundcube · webmail5 авг. 2024 г.
- CVE-2021-4402690Срочно
Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 70 %roundcube · webmail19 нояб. 2021 г.
- CVE-2020-1396577На этой неделе
An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5.
СредняяCVSS 6,1KEVГотовый эксплойтEPSS 77 %roundcube · webmail8 июн. 2020 г.
- CVE-2024-3738376На этой неделе
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.
СредняяCVSS 6,1KEVГотовый эксплойтEPSS 73 %roundcube · webmail7 июн. 2024 г.
- CVE-2017-1665175На этой неделе
Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's file
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 46 %roundcube · webmail9 нояб. 2017 г.
- CVE-2023-563174На этой неделе
Stored XSS vulnerability in Roundcube
СредняяCVSS 5,4KEVГотовый эксплойтEPSS 76 %roundcube · webmail18 окт. 2023 г.
- CVE-2023-4377073На этой неделе
Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of
СредняяCVSS 6,1KEVГотовый эксплойтEPSS 64 %roundcube · webmail22 сент. 2023 г.
- CVE-2020-3573064На этой неделе
An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10.
СредняяCVSS 6,1KEVГотовый эксплойтEPSS 33 %roundcube · webmail28 дек. 2020 г.
- CVE-2025-6846162На этой неделе
Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG d
СредняяCVSS 6,1KEVГотовый эксплойтEPSS 27 %roundcube · webmail18 дек. 2025 г.
- CVE-2008-561958В плане
html2text.php in Chuggnutt HTML to Text Converter, as used in PHPMailer before 5.2.10, RoundCube Webmail (roundcubemail) 0.2-1.alpha and 0.2
КритическаяCVSS 10,0Proof of conceptEPSS 59 %roundcube · webmail16 дек. 2008 г.
- CVE-2024-4201050В плане
mod_css_styles in Roundcube through 1.5.7 and 1.6.x through 1.6.7 insufficiently filters Cascading Style Sheets (CSS) token sequences in ren
ВысокаяCVSS 7,5Эксплойта нетEPSS 67 %5 авг. 2024 г.
- CVE-2024-4200847В плане
A Cross-Site Scripting vulnerability in rcmail_action_mail_get->run() in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote att
КритическаяCVSS 9,3Proof of conceptEPSS 34 %roundcube · webmail5 авг. 2024 г.
- CVE-2018-1920641В плане
steps/mail/func.inc in Roundcube before 1.3.8 has XSS via crafted use of <svg><style>, as demonstrated by an onload attribute in a BODY elem
СредняяCVSS 6,1Эксплойта нетEPSS 56 %roundcube · webmail12 нояб. 2018 г.
- CVE-2020-1264041В плане
Roundcube Webmail before 1.4.4 allows attackers to include local files and execute code via directory traversal in a plugin name to rcube_pl
КритическаяCVSS 9,8Proof of conceptEPSS 7 %roundcube · webmail4 мая 2020 г.
- CVE-2026-6264340В плане
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages ma
КритическаяCVSS 10,0Эксплойта нетEPSS 0 %roundcube · webmail14 июл. 2026 г.
- CVE-2026-5443340В плане
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafted plain-text email message
КритическаяCVSS 10,0Proof of conceptEPSS 0 %roundcube · webmail14 июл. 2026 г.
- CVE-2024-3738539Наблюдать
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 on Windows allows command injection via im_convert_path and im_identify_path.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %roundcube · webmail7 июн. 2024 г.
- CVE-2026-7500339Наблюдать
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed url() in a FuncIRI attribute of an SVG image could evade the remote i
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %roundcube · webmail17 авг. 2026 г.
- CVE-2026-6264439Наблюдать
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing via
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %roundcube · webmail14 июл. 2026 г.
- CVE-2015-877037Наблюдать
Directory traversal vulnerability in the set_skin function in program/include/rcmail_output_html.php in Roundcube before 1.0.8 and 1.1.x bef
ВысокаяCVSS 7,5Proof of conceptEPSS 22 %roundcube · roundcube webmail29 янв. 2016 г.
- CVE-2015-218036Наблюдать
The DBMail driver in the Password plugin in Roundcube before 1.1.0 allows remote attackers to execute arbitrary commands via shell metachara
ВысокаяCVSS 8,8Эксплойта нетEPSS 5 %roundcube · webmail30 янв. 2017 г.
- CVE-2017-811436Наблюдать
Roundcube Webmail allows arbitrary password resets by authenticated users.
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %roundcube · webmail29 апр. 2017 г.
- CVE-2015-218136Наблюдать
Multiple buffer overflows in the DBMail driver in the Password plugin in Roundcube before 1.1.0 allow remote attackers to have unspecified i
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %roundcube · webmail30 янв. 2017 г.