Roundcube / Webmail
95 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-75010 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the modoboa driver of the password plugin could leak a Modoboa API authentication token to a user-co… | MEDIUM | 6.4 | Aug 17, 2026 |
| CVE-2026-75007 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the LDAP search filter was subject to injection via unescaped %u/%fu/%d substitution, which may lead… | HIGH | 8.8 | Aug 17, 2026 |
| CVE-2026-75006 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or I… | MEDIUM | 5.8 | Aug 17, 2026 |
| CVE-2026-75004 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper rule name quoting could lead to managesieve_disabled_actions setting bypass via a crafted r… | MEDIUM | 4.3 | Aug 17, 2026 |
| CVE-2026-75003 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed url() in a FuncIRI attribute of an SVG image could evade the remote image blocking, whic… | CRITICAL | 9.8 | Aug 17, 2026 |
| CVE-2026-75002 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, mail search and LITERAL+ byte-count desynchronization could lead to information disclosure or privil… | HIGH | 7.1 | Aug 17, 2026 |
| CVE-2026-75000 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper HTML/CSS sanitization of the SVG animate "by" attribute may lead to remote image blocking b… | MEDIUM | 5.8 | Aug 17, 2026 |
| CVE-2026-74999 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the "Add to address book" action was subject to stored XSS. | MEDIUM | 5.4 | Aug 17, 2026 |
| CVE-2026-74998 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, responses from the CSS (Cascading Style Sheets) proxy were not validated, which may result in inform… | HIGH | 7.2 | Aug 17, 2026 |
| CVE-2026-74997 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the cmd_learn driver of the markasjunk plugin is subject to remote code execution via crafted placeh… | HIGH | 8.8 | Aug 17, 2026 |
| CVE-2026-54432 | Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2 allows Stored Cross-Site Scripting (XSS). The issue occurs because the attachment MIME type is not prope… | MEDIUM | 4.7 | Jul 14, 2026 |
| CVE-2026-54433 | In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafted plain-text email message. The attacker-cont… | CRITICAL | 10.0 | Jul 14, 2026 |
| CVE-2026-62644 | In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing via session data, whic… | CRITICAL | 9.8 | Jul 14, 2026 |
| CVE-2026-62643 | In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or I… | CRITICAL | 10.0 | Jul 14, 2026 |
| CVE-2026-62642 | In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, an infinite loop was discovered in the TNEF decoder, which may lead to denial of service upon openin… | MEDIUM | 6.5 | Jul 14, 2026 |
| CVE-2026-62641 | In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the TNEF decoder was subject to denial of service via a crafted compressed-RTF size. | MEDIUM | 6.5 | Jul 14, 2026 |
| CVE-2026-48849 | In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, an unsanitized subject field in the draft restored value could lead to stored XSS/HTML/CSS inj… | MEDIUM | 4.4 | May 25, 2026 |
| CVE-2026-48848 | Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7 has insufficient HTML sanitization that could lead to Cascading Style Sheets (CSS) injection via an… | HIGH | 7.2 | May 25, 2026 |
| CVE-2026-48847 | Roundcube Webmail 1.6.x before 1.6.16, and 1.7.x before 1.7.1 allows pre-authentication arbitrary file deletion via redis/memcache session poisoning bypass. | LOW | 3.7 | May 25, 2026 |
| CVE-2026-48846 | In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, the remote image blocking feature can be bypassed via a crafted CSS var() value in an e-mail m… | MEDIUM | 6.5 | May 25, 2026 |
| CVE-2026-48845 | In Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16 and 1.7.x before 1.7.1, remote image blocking was not honored for URLs pointing to local/private destinati… | MEDIUM | 6.5 | May 25, 2026 |
| CVE-2026-48844 | Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has insecure code evaluation logic in LDAP the autovalues option that could lead to code injection… | HIGH | 7.5 | May 25, 2026 |
| CVE-2026-48843 | Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16,and 1.7.x before 1.7.1 has Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may… | HIGH | 7.2 | May 25, 2026 |
| CVE-2026-48842 | Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via a preg_replace() backslash e… | HIGH | 8.1 | May 25, 2026 |
| CVE-2026-35545 | An issue was discovered in Roundcube Webmail before 1.5.15 and 1.6.15. The remote image blocking feature can be bypassed via SVG content in an e-mail message.… | HIGH | 8.2 | Apr 3, 2026 |
Showing 1 to 25 of 95 CVEs