📦

webmail

Vendor: roundcube

Actively Exploited 11 CISA KEV List
PoC / Exploits 15 Code Available
Total RCEs 7 Remote Access
Total CVEs 551 Total Indexed
Avg. EPSS 11.66% Exploit Prob.
Latest CVE CVE-2026-54433 Jul 14

Security Vulnerability Index

Page 2 / 56
5.4 CVSS

An issue was discovered in Roundcube Webmail 1.6.0 before 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts.

EPSS: 0.31%
6.1 CVSS

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. XSS exists because of insufficient HTML attachment sanitization in preview mode. A victim must preview a text/html attachment.

EPSS: 0.25%
3.1 CVSS

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsanitized IMAP SEARCH command arguments could lead to IMAP injection or CSRF bypass during mail search.

EPSS: 0.28%
3.7 CVSS

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsafe deserialization in the redis/memcache session handler may lead to arbitrary file write operations by unauthenticated attackers via crafted session data.

EPSS: 0.47%
7.2 CVSS
CVE-2025-68461
Exploit Found

Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document.

EPSS: 20.09%
7.2 CVSS

Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a information disclosure vulnerability in the HTML style sanitizer.

EPSS: 0.25%
Critical Target
9.9 CVSS
CVE-2025-49113
RCE Exploit Found

Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP Object Deserialization.

EPSS: 96.78%
6.1 CVSS

Cross-Site Scripting (XSS) vulnerability in Roundcube Webmail 1.6.9 allows remote authenticated users to upload a malicious file as an email attachment, leading to the triggering of the XSS by visiting the SENT session.

EPSS: 28.82%
9.3 CVSS
CVE-2024-42009
Exploit Found

A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a crafted e-mail message that abuses a Desanitization issue in message_body() in program/actions/mail/show.php.

EPSS: 79.62%
9.3 CVSS
CVE-2024-42008
Exploit Found

A Cross-Site Scripting vulnerability in rcmail_action_mail_get->run() in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a malicious e-mail attachment served with a dangerous Content-Type header.

EPSS: 34.21%