CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1 (more results available)

CVE-2026-75010 MEDIUM

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the modoboa driver of the password plugin could leak a Modoboa API authentication token to a user-co…

CVSS 6.4 EPSS 0.39% Aug 17, 2026
CVE-2026-75007 HIGH

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the LDAP search filter was subject to injection via unescaped %u/%fu/%d substitution, which may lead…

CVSS 8.8 EPSS 0.50% Aug 17, 2026
CVE-2026-75006 MEDIUM

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or I…

CVSS 5.8 EPSS 0.56% Aug 17, 2026
CVE-2026-75004 MEDIUM

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper rule name quoting could lead to managesieve_disabled_actions setting bypass via a crafted r…

CVSS 4.3 EPSS 0.37% Aug 17, 2026
CVE-2026-75003 CRITICAL

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed url() in a FuncIRI attribute of an SVG image could evade the remote image blocking, whic…

CVSS 9.8 EPSS 0.58% Aug 17, 2026
CVE-2026-75002 HIGH

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, mail search and LITERAL+ byte-count desynchronization could lead to information disclosure or privil…

CVSS 7.1 EPSS 2.28% Aug 17, 2026
CVE-2026-75000 MEDIUM

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper HTML/CSS sanitization of the SVG animate "by" attribute may lead to remote image blocking b…

CVSS 5.8 EPSS 0.47% Aug 17, 2026
CVE-2026-74999 MEDIUM

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the "Add to address book" action was subject to stored XSS.

CVSS 5.4 EPSS 0.30% Aug 17, 2026
CVE-2026-74998 HIGH

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, responses from the CSS (Cascading Style Sheets) proxy were not validated, which may result in inform…

CVSS 7.2 EPSS 0.44% Aug 17, 2026
CVE-2026-74997 HIGH

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the cmd_learn driver of the markasjunk plugin is subject to remote code execution via crafted placeh…

CVSS 8.8 EPSS 1.13% Aug 17, 2026
CVE-2026-54432 MEDIUM

Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2 allows Stored Cross-Site Scripting (XSS). The issue occurs because the attachment MIME type is not prope…

CVSS 4.7 EPSS 0.21% Jul 14, 2026
CVE-2026-54433 CRITICAL

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafted plain-text email message. The attacker-cont…

CVSS 10.0 EPSS 0.31% Jul 14, 2026
CVE-2026-62644 CRITICAL

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing via session data, whic…

CVSS 9.8 EPSS 0.50% Jul 14, 2026
CVE-2026-62643 CRITICAL

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or I…

CVSS 10.0 EPSS 0.44% Jul 14, 2026
CVE-2026-62642 MEDIUM

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, an infinite loop was discovered in the TNEF decoder, which may lead to denial of service upon openin…

CVSS 6.5 EPSS 0.52% Jul 14, 2026
CVE-2026-62641 MEDIUM

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the TNEF decoder was subject to denial of service via a crafted compressed-RTF size.

CVSS 6.5 EPSS 0.47% Jul 14, 2026
CVE-2026-48849 MEDIUM

In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, an unsanitized subject field in the draft restored value could lead to stored XSS/HTML/CSS inj…

CVSS 4.4 EPSS 0.26% May 25, 2026
CVE-2026-48848 HIGH

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7 has insufficient HTML sanitization that could lead to Cascading Style Sheets (CSS) injection via an…

CVSS 7.2 EPSS 0.45% May 25, 2026
CVE-2026-48847 LOW

Roundcube Webmail 1.6.x before 1.6.16, and 1.7.x before 1.7.1 allows pre-authentication arbitrary file deletion via redis/memcache session poisoning bypass.

CVSS 3.7 EPSS 0.54% May 25, 2026
CVE-2026-48846 MEDIUM

In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, the remote image blocking feature can be bypassed via a crafted CSS var() value in an e-mail m…

CVSS 6.5 EPSS 0.48% May 25, 2026
CVE-2026-48845 MEDIUM

In Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16 and 1.7.x before 1.7.1, remote image blocking was not honored for URLs pointing to local/private destinati…

CVSS 6.5 EPSS 0.45% May 25, 2026
CVE-2026-48844 HIGH

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has insecure code evaluation logic in LDAP the autovalues option that could lead to code injection…

CVSS 7.5 EPSS 0.51% May 25, 2026
CVE-2026-48843 HIGH

Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16,and 1.7.x before 1.7.1 has Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may…

CVSS 7.2 EPSS 0.46% May 25, 2026
CVE-2026-48842 HIGH

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via a preg_replace() backslash e…

CVSS 8.1 EPSS 0.89% May 25, 2026
CVE-2026-35545 HIGH

An issue was discovered in Roundcube Webmail before 1.5.15 and 1.6.15. The remote image blocking feature can be bypassed via SVG content in an e-mail message.…

CVSS 8.2 EPSS 0.55% Apr 3, 2026

Showing 1 to 25 CVEs · page 1 (more available)