Roundcube kayıtları
roundcube üreticisine ait 99 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 11 · %11,1
- Silahlaştırılmış
- 11 · %11,1
- Pre-auth RCE
- 4
- Düzeltme kaydı olan
- %93,9
- Yayından KEV’e ortanca
- 308 gün
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')42
- CWE-669 Incorrect Resource Transfer Between Spheres8
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor6
- CWE-352 Cross-Site Request Forgery (CSRF)5
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')4
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWEBug bounty kapsamı
Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.
Tüm kayıtlar
99 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
95Hemen | CVE-2025-49113Silahlaştırılmış | Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in aroundcube · webmail · CWE-502 | Yüksek8,8 | KEV | %98,9 | 2 Haz 2025 |
94Hemen | CVE-2020-12641Silahlaştırılmış | rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setroundcube · webmail · CWE-78 | Kritik9,8 | KEV | %84,3 | 4 May 2020 |
92Hemen | CVE-2024-42009Silahlaştırılmış | A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails ofroundcube · webmail · CWE-79 | Kritik9,3 | KEV | %82,9 | 5 Ağu 2024 |
90Hemen | CVE-2021-44026Silahlaştırılmış | Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.roundcube · webmail · CWE-89 | Kritik9,8 | KEV | %69,9 | 19 Kas 2021 |
77Bu hafta | CVE-2020-13965Silahlaştırılmış | An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5.roundcube · webmail · CWE-79 | Orta6,1 | KEV | %76,6 | 8 Haz 2020 |
76Bu hafta | CVE-2024-37383Silahlaştırılmış | Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.roundcube · webmail · CWE-79 | Orta6,1 | KEV | %73,3 | 7 Haz 2024 |
75Bu hafta | CVE-2017-16651Silahlaştırılmış | Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's fileroundcube · webmail · CWE-552 | Yüksek7,8 | KEV | %45,7 | 9 Kas 2017 |
74Bu hafta | CVE-2023-5631Silahlaştırılmış | Stored XSS vulnerability in Roundcuberoundcube · webmail · CWE-79 | Orta5,4 | KEV | %75,9 | 18 Eki 2023 |
73Bu hafta | CVE-2023-43770Silahlaştırılmış | Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of roundcube · webmail · CWE-79 | Orta6,1 | KEV | %63,7 | 22 Eyl 2023 |
64Bu hafta | CVE-2020-35730Silahlaştırılmış | An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10.roundcube · webmail · CWE-79 | Orta6,1 | KEV | %32,7 | 28 Ara 2020 |
62Bu hafta | CVE-2025-68461Silahlaştırılmış | Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG droundcube · webmail · CWE-79 | Orta6,1 | KEV | %26,8 | 18 Ara 2025 |
58Planlayın | CVE-2008-5619Kavram kanıtı | html2text.php in Chuggnutt HTML to Text Converter, as used in PHPMailer before 5.2.10, RoundCube Webmail (roundcubemail) 0.2-1.alpha and 0.2roundcube · webmail · CWE-94 | Kritik10,0 | — | %58,6 | 16 Ara 2008 |
50Planlayın | CVE-2024-42010İstismar yok | mod_css_styles in Roundcube through 1.5.7 and 1.6.x through 1.6.7 insufficiently filters Cascading Style Sheets (CSS) token sequences in renCWE-200 | Yüksek7,5 | — | %66,7 | 5 Ağu 2024 |
47Planlayın | CVE-2024-42008Kavram kanıtı | A Cross-Site Scripting vulnerability in rcmail_action_mail_get->run() in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attroundcube · webmail · CWE-79 | Kritik9,3 | — | %34,2 | 5 Ağu 2024 |
41Planlayın | CVE-2018-19206İstismar yok | steps/mail/func.inc in Roundcube before 1.3.8 has XSS via crafted use of <svg><style>, as demonstrated by an onload attribute in a BODY elemroundcube · webmail · CWE-79 | Orta6,1 | — | %55,9 | 12 Kas 2018 |
41Planlayın | CVE-2020-12640Kavram kanıtı | Roundcube Webmail before 1.4.4 allows attackers to include local files and execute code via directory traversal in a plugin name to rcube_plroundcube · webmail · CWE-22 | Kritik9,8 | — | %6,7 | 4 May 2020 |
40Planlayın | CVE-2026-62643İstismar yok | In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages maroundcube · webmail · CWE-918 | Kritik10,0 | — | %0,4 | 14 Tem 2026 |
40Planlayın | CVE-2026-54433Kavram kanıtı | In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafted plain-text email messageroundcube · webmail · CWE-79 | Kritik10,0 | — | %0,3 | 14 Tem 2026 |
39İzleyin | CVE-2024-37385İstismar yok | Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 on Windows allows command injection via im_convert_path and im_identify_path.roundcube · webmail · CWE-77 | Kritik9,8 | — | %1,5 | 7 Haz 2024 |
39İzleyin | CVE-2026-75003İstismar yok | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed url() in a FuncIRI attribute of an SVG image could evade the remote iroundcube · webmail · CWE-669 | Kritik9,8 | — | %0,6 | 17 Ağu 2026 |
39İzleyin | CVE-2026-62644İstismar yok | In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing viaroundcube · webmail · CWE-290 | Kritik9,8 | — | %0,5 | 14 Tem 2026 |
37İzleyin | CVE-2015-8770Kavram kanıtı | Directory traversal vulnerability in the set_skin function in program/include/rcmail_output_html.php in Roundcube before 1.0.8 and 1.1.x befroundcube · roundcube webmail · CWE-22 | Yüksek7,5 | — | %22,4 | 29 Oca 2016 |
36İzleyin | CVE-2015-2180İstismar yok | The DBMail driver in the Password plugin in Roundcube before 1.1.0 allows remote attackers to execute arbitrary commands via shell metachararoundcube · webmail · CWE-74 | Yüksek8,8 | — | %4,7 | 30 Oca 2017 |
36İzleyin | CVE-2017-8114İstismar yok | Roundcube Webmail allows arbitrary password resets by authenticated users.roundcube · webmail · CWE-269 | Yüksek8,8 | — | %3,5 | 29 Nis 2017 |
36İzleyin | CVE-2015-2181İstismar yok | Multiple buffer overflows in the DBMail driver in the Password plugin in Roundcube before 1.1.0 allow remote attackers to have unspecified iroundcube · webmail · CWE-119 | Yüksek8,8 | — | %2,9 | 30 Oca 2017 |
- CVE-2025-4911395Hemen
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %99roundcube · webmail2 Haz 2025
- CVE-2020-1264194Hemen
rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration set
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %84roundcube · webmail4 May 2020
- CVE-2024-4200992Hemen
A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of
KritikCVSS 9,3KEVSilahlaştırılmışEPSS %83roundcube · webmail5 Ağu 2024
- CVE-2021-4402690Hemen
Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %70roundcube · webmail19 Kas 2021
- CVE-2020-1396577Bu hafta
An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5.
OrtaCVSS 6,1KEVSilahlaştırılmışEPSS %77roundcube · webmail8 Haz 2020
- CVE-2024-3738376Bu hafta
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.
OrtaCVSS 6,1KEVSilahlaştırılmışEPSS %73roundcube · webmail7 Haz 2024
- CVE-2017-1665175Bu hafta
Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's file
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %46roundcube · webmail9 Kas 2017
- CVE-2023-563174Bu hafta
Stored XSS vulnerability in Roundcube
OrtaCVSS 5,4KEVSilahlaştırılmışEPSS %76roundcube · webmail18 Eki 2023
- CVE-2023-4377073Bu hafta
Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of
OrtaCVSS 6,1KEVSilahlaştırılmışEPSS %64roundcube · webmail22 Eyl 2023
- CVE-2020-3573064Bu hafta
An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10.
OrtaCVSS 6,1KEVSilahlaştırılmışEPSS %33roundcube · webmail28 Ara 2020
- CVE-2025-6846162Bu hafta
Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG d
OrtaCVSS 6,1KEVSilahlaştırılmışEPSS %27roundcube · webmail18 Ara 2025
- CVE-2008-561958Planlayın
html2text.php in Chuggnutt HTML to Text Converter, as used in PHPMailer before 5.2.10, RoundCube Webmail (roundcubemail) 0.2-1.alpha and 0.2
KritikCVSS 10,0Kavram kanıtıEPSS %59roundcube · webmail16 Ara 2008
- CVE-2024-4201050Planlayın
mod_css_styles in Roundcube through 1.5.7 and 1.6.x through 1.6.7 insufficiently filters Cascading Style Sheets (CSS) token sequences in ren
YüksekCVSS 7,5İstismar yokEPSS %675 Ağu 2024
- CVE-2024-4200847Planlayın
A Cross-Site Scripting vulnerability in rcmail_action_mail_get->run() in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote att
KritikCVSS 9,3Kavram kanıtıEPSS %34roundcube · webmail5 Ağu 2024
- CVE-2018-1920641Planlayın
steps/mail/func.inc in Roundcube before 1.3.8 has XSS via crafted use of <svg><style>, as demonstrated by an onload attribute in a BODY elem
OrtaCVSS 6,1İstismar yokEPSS %56roundcube · webmail12 Kas 2018
- CVE-2020-1264041Planlayın
Roundcube Webmail before 1.4.4 allows attackers to include local files and execute code via directory traversal in a plugin name to rcube_pl
KritikCVSS 9,8Kavram kanıtıEPSS %7roundcube · webmail4 May 2020
- CVE-2026-6264340Planlayın
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages ma
KritikCVSS 10,0İstismar yokEPSS %0roundcube · webmail14 Tem 2026
- CVE-2026-5443340Planlayın
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafted plain-text email message
KritikCVSS 10,0Kavram kanıtıEPSS %0roundcube · webmail14 Tem 2026
- CVE-2024-3738539İzleyin
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 on Windows allows command injection via im_convert_path and im_identify_path.
KritikCVSS 9,8İstismar yokEPSS %1roundcube · webmail7 Haz 2024
- CVE-2026-7500339İzleyin
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed url() in a FuncIRI attribute of an SVG image could evade the remote i
KritikCVSS 9,8İstismar yokEPSS %1roundcube · webmail17 Ağu 2026
- CVE-2026-6264439İzleyin
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing via
KritikCVSS 9,8İstismar yokEPSS %1roundcube · webmail14 Tem 2026
- CVE-2015-877037İzleyin
Directory traversal vulnerability in the set_skin function in program/include/rcmail_output_html.php in Roundcube before 1.0.8 and 1.1.x bef
YüksekCVSS 7,5Kavram kanıtıEPSS %22roundcube · roundcube webmail29 Oca 2016
- CVE-2015-218036İzleyin
The DBMail driver in the Password plugin in Roundcube before 1.1.0 allows remote attackers to execute arbitrary commands via shell metachara
YüksekCVSS 8,8İstismar yokEPSS %5roundcube · webmail30 Oca 2017
- CVE-2017-811436İzleyin
Roundcube Webmail allows arbitrary password resets by authenticated users.
YüksekCVSS 8,8İstismar yokEPSS %3roundcube · webmail29 Nis 2017
- CVE-2015-218136İzleyin
Multiple buffer overflows in the DBMail driver in the Password plugin in Roundcube before 1.1.0 allow remote attackers to have unspecified i
YüksekCVSS 8,8İstismar yokEPSS %3roundcube · webmail30 Oca 2017