Webmail

Roundcube · 95 CVEs

CVE-2026-75010
MEDIUM

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the modoboa driver of the password plugin could leak a Modob…

Aug 17, 2026

CVE-2026-75007
HIGH

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the LDAP search filter was subject to injection via unescape…

Aug 17, 2026

CVE-2026-75006
MEDIUM

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, insufficient Cascading Style Sheets (CSS) sanitization in HT…

Aug 17, 2026

CVE-2026-75004
MEDIUM

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper rule name quoting could lead to managesieve_disable…

Aug 17, 2026

CVE-2026-75003
CRITICAL

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed url() in a FuncIRI attribute of an SVG image cou…

Aug 17, 2026

CVE-2026-75002
HIGH

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, mail search and LITERAL+ byte-count desynchronization could…

Aug 17, 2026

CVE-2026-75000
MEDIUM

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper HTML/CSS sanitization of the SVG animate "by" attri…

Aug 17, 2026

CVE-2026-74999
MEDIUM

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the "Add to address book" action was subject to stored XSS.

Aug 17, 2026

CVE-2026-74998
HIGH

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, responses from the CSS (Cascading Style Sheets) proxy were n…

Aug 17, 2026

CVE-2026-74997
HIGH

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the cmd_learn driver of the markasjunk plugin is subject to…

Aug 17, 2026

CVE-2026-54432
MEDIUM

Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2 allows Stored Cross-Site Scripting (XSS). The issue occurs becau…

Jul 14, 2026

CVE-2026-54433
CRITICAL

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafted pla…

Jul 14, 2026

CVE-2026-62644
CRITICAL

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to…

Jul 14, 2026

CVE-2026-62643
CRITICAL

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sheets (CSS) sanitization in HT…

Jul 14, 2026

CVE-2026-62642
MEDIUM

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, an infinite loop was discovered in the TNEF decoder, which m…

Jul 14, 2026

CVE-2026-62641
MEDIUM

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the TNEF decoder was subject to denial of service via a craf…

Jul 14, 2026

CVE-2026-48849
MEDIUM

In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, an unsanitized subject field in the draft restored val…

May 25, 2026

CVE-2026-48848
HIGH

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7 has insufficient HTML sanitization that could lead to Cascad…

May 25, 2026

CVE-2026-48847
LOW

Roundcube Webmail 1.6.x before 1.6.16, and 1.7.x before 1.7.1 allows pre-authentication arbitrary file deletion via red…

May 25, 2026

CVE-2026-48846
MEDIUM

In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, the remote image blocking feature can be bypassed via…

May 25, 2026

CVE-2026-48845
MEDIUM

In Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16 and 1.7.x before 1.7.1, remote image blocking was not honored for…

May 25, 2026

CVE-2026-48844
HIGH

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has insecure code evaluation logic in LDAP the autovalues…

May 25, 2026

CVE-2026-48843
HIGH

Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16,and 1.7.x before 1.7.1 has Insufficient Cascading Style Sheets (CSS)…

May 25, 2026

CVE-2026-48842
HIGH

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query…

May 25, 2026

CVE-2026-35545
HIGH

An issue was discovered in Roundcube Webmail before 1.5.15 and 1.6.15. The remote image blocking feature can be bypasse…

Apr 3, 2026

Showing 1 to 25 of 95 CVEs