İçeriğe atla
Noroxi

Roundcube kayıtları

roundcube üreticisine ait 99 yayımlanmış kayıt.

Bug bounty kapsamı

Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.

Tüm kayıtlar

99 kayıt
  • Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %99

    roundcube · webmail2 Haz 2025

  • rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration set

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %84

    roundcube · webmail4 May 2020

  • A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of

    KritikCVSS 9,3KEVSilahlaştırılmışEPSS %83

    roundcube · webmail5 Ağu 2024

  • Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %70

    roundcube · webmail19 Kas 2021

  • CVE-2020-13965
    77Bu hafta

    An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5.

    OrtaCVSS 6,1KEVSilahlaştırılmışEPSS %77

    roundcube · webmail8 Haz 2020

  • CVE-2024-37383
    76Bu hafta

    Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.

    OrtaCVSS 6,1KEVSilahlaştırılmışEPSS %73

    roundcube · webmail7 Haz 2024

  • CVE-2017-16651
    75Bu hafta

    Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's file

    YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %46

    roundcube · webmail9 Kas 2017

  • CVE-2023-5631
    74Bu hafta

    Stored XSS vulnerability in Roundcube

    OrtaCVSS 5,4KEVSilahlaştırılmışEPSS %76

    roundcube · webmail18 Eki 2023

  • CVE-2023-43770
    73Bu hafta

    Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of

    OrtaCVSS 6,1KEVSilahlaştırılmışEPSS %64

    roundcube · webmail22 Eyl 2023

  • CVE-2020-35730
    64Bu hafta

    An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10.

    OrtaCVSS 6,1KEVSilahlaştırılmışEPSS %33

    roundcube · webmail28 Ara 2020

  • CVE-2025-68461
    62Bu hafta

    Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG d

    OrtaCVSS 6,1KEVSilahlaştırılmışEPSS %27

    roundcube · webmail18 Ara 2025

  • CVE-2008-5619
    58Planlayın

    html2text.php in Chuggnutt HTML to Text Converter, as used in PHPMailer before 5.2.10, RoundCube Webmail (roundcubemail) 0.2-1.alpha and 0.2

    KritikCVSS 10,0Kavram kanıtıEPSS %59

    roundcube · webmail16 Ara 2008

  • CVE-2024-42010
    50Planlayın

    mod_css_styles in Roundcube through 1.5.7 and 1.6.x through 1.6.7 insufficiently filters Cascading Style Sheets (CSS) token sequences in ren

    YüksekCVSS 7,5İstismar yokEPSS %67

    5 Ağu 2024

  • CVE-2024-42008
    47Planlayın

    A Cross-Site Scripting vulnerability in rcmail_action_mail_get->run() in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote att

    KritikCVSS 9,3Kavram kanıtıEPSS %34

    roundcube · webmail5 Ağu 2024

  • CVE-2018-19206
    41Planlayın

    steps/mail/func.inc in Roundcube before 1.3.8 has XSS via crafted use of <svg><style>, as demonstrated by an onload attribute in a BODY elem

    OrtaCVSS 6,1İstismar yokEPSS %56

    roundcube · webmail12 Kas 2018

  • CVE-2020-12640
    41Planlayın

    Roundcube Webmail before 1.4.4 allows attackers to include local files and execute code via directory traversal in a plugin name to rcube_pl

    KritikCVSS 9,8Kavram kanıtıEPSS %7

    roundcube · webmail4 May 2020

  • CVE-2026-62643
    40Planlayın

    In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages ma

    KritikCVSS 10,0İstismar yokEPSS %0

    roundcube · webmail14 Tem 2026

  • CVE-2026-54433
    40Planlayın

    In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafted plain-text email message

    KritikCVSS 10,0Kavram kanıtıEPSS %0

    roundcube · webmail14 Tem 2026

  • CVE-2024-37385
    39İzleyin

    Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 on Windows allows command injection via im_convert_path and im_identify_path.

    KritikCVSS 9,8İstismar yokEPSS %1

    roundcube · webmail7 Haz 2024

  • CVE-2026-75003
    39İzleyin

    In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed url() in a FuncIRI attribute of an SVG image could evade the remote i

    KritikCVSS 9,8İstismar yokEPSS %1

    roundcube · webmail17 Ağu 2026

  • CVE-2026-62644
    39İzleyin

    In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing via

    KritikCVSS 9,8İstismar yokEPSS %1

    roundcube · webmail14 Tem 2026

  • CVE-2015-8770
    37İzleyin

    Directory traversal vulnerability in the set_skin function in program/include/rcmail_output_html.php in Roundcube before 1.0.8 and 1.1.x bef

    YüksekCVSS 7,5Kavram kanıtıEPSS %22

    roundcube · roundcube webmail29 Oca 2016

  • CVE-2015-2180
    36İzleyin

    The DBMail driver in the Password plugin in Roundcube before 1.1.0 allows remote attackers to execute arbitrary commands via shell metachara

    YüksekCVSS 8,8İstismar yokEPSS %5

    roundcube · webmail30 Oca 2017

  • CVE-2017-8114
    36İzleyin

    Roundcube Webmail allows arbitrary password resets by authenticated users.

    YüksekCVSS 8,8İstismar yokEPSS %3

    roundcube · webmail29 Nis 2017

  • CVE-2015-2181
    36İzleyin

    Multiple buffer overflows in the DBMail driver in the Password plugin in Roundcube before 1.1.0 allow remote attackers to have unspecified i

    YüksekCVSS 8,8İstismar yokEPSS %3

    roundcube · webmail30 Oca 2017