📦

webmail

Vendor: roundcube

Actively Exploited 11 CISA KEV List
PoC / Exploits 15 Code Available
Total RCEs 7 Remote Access
Total CVEs 551 Total Indexed
Avg. EPSS 11.66% Exploit Prob.
Latest CVE CVE-2026-54433 Jul 14

Security Vulnerability Index

Page 3 / 56
9.8 CVSS

Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 on Windows allows command injection via im_convert_path and im_identify_path. NOTE: this issue exists because of an incomplete fix for CVE-2020-12641.

EPSS: 1.48%
6.1 CVSS

Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via list columns from user preferences.

EPSS: 0.50%
6.1 CVSS
CVE-2024-37383
Exploit Found

Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.

EPSS: 73.30%
6.1 CVSS

Roundcube 1.5.x before 1.5.6 and 1.6.x before 1.6.5 allows XSS via a Content-Type or Content-Disposition header (used for attachment preview or download).

EPSS: 0.64%
6.1 CVSS

Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a crafted SVG document because of program/lib/Roundcube/rcube_washtml.php behavior. This could allow a remote attacker to load arbitrary JavaScript code.

EPSS: 75.87%
6.1 CVSS

Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of program/lib/Roundcube/rcube_string_replacer.php behavior.

EPSS: 58.48%
9.8 CVSS
CVE-2021-44026
Exploit Found

Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.

EPSS: 42.75%
6.1 CVSS

Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to XSS in handling an attachment's filename extension when displaying a MIME type warning message.

EPSS: 1.05%
5.4 CVSS

Cross Site Scripting (XSS) vulnerability in Roundcube Mail <=1.4.4 via smtp config in /installer/test.php.

EPSS: 0.81%
5.4 CVSS

Cross Site Scripting (XSS) vulneraibility in Roundcube mail .4.4 via database host and user in /installer/test.php.

EPSS: 0.92%