Aleksander Machniak

92 exploits Active since Aug 2012
CVE-2026-48847 WRITEUP LOW WRITEUP
Roundcube Webmail - Incorrect Resource Transfer Between Spheres
Roundcube Webmail 1.6.x before 1.6.16, and 1.7.x before 1.7.1 allows pre-authentication arbitrary file deletion via redis/memcache session poisoning bypass.
CVSS 3.7
CVE-2026-48848 WRITEUP HIGH WRITEUP
Roundcube Webmail - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7 has insufficient HTML sanitization that could lead to Cascading Style Sheets (CSS) injection via an SVG document that has an animate element with the attributeName attribute.
CVSS 7.2
CVE-2026-48849 WRITEUP MEDIUM WRITEUP
Roundcube Webmail - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, an unsanitized subject field in the draft restored value could lead to stored XSS/HTML/CSS injection on shared mailboxes.
CVSS 4.4
CVE-2012-4668 WRITEUP WRITEUP
Roundcube Webmail < 0.8.1 - Cross-Site Scripting via Email Signature
Cross-site scripting (XSS) vulnerability in Roundcube Webmail 0.8.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the signature in an email.
CVE-2015-5382 WRITEUP MEDIUM WRITEUP
Roundcube Webmail <1.0.6, <1.1.2 - Info Disclosure
program/steps/addressbook/photo.inc in Roundcube Webmail before 1.0.6 and 1.1.x before 1.1.2 allows remote authenticated users to read arbitrary files via the _alt parameter when uploading a vCard.
CVSS 6.5
CVE-2017-6820 WRITEUP MEDIUM WRITEUP
Roundcube Webmail < 1.1.8 and 1.2.x < 1.2.4 - Cross-Site Scripting via SVG CSS Token Sequence
rcube_utils.php in Roundcube before 1.1.8 and 1.2.x before 1.2.4 is susceptible to a cross-site scripting vulnerability via a crafted Cascading Style Sheets (CSS) token sequence within an SVG element.
CVSS 6.1
CVE-2020-12625 WRITEUP MEDIUM WRITEUP
Roundcube Webmail < 1.4.4 - Stored Cross-Site Scripting via HTML Message CDATA
An issue was discovered in Roundcube Webmail before 1.4.4. There is a cross-site scripting (XSS) vulnerability in rcube_washtml.php because JavaScript code can occur in the CDATA of an HTML message.
CVSS 6.1
CVE-2020-12640 WRITEUP CRITICAL WRITEUP
Roundcube Webmail <1.4.4 - Path Traversal
Roundcube Webmail before 1.4.4 allows attackers to include local files and execute code via directory traversal in a plugin name to rcube_plugin_api.php.
CVSS 9.8
CVE-2020-12641 WRITEUP CRITICAL WRITEUP
Roundcube Webmail < 1.4.4 - Remote Code Execution via Shell Metacharacters in Image Configuration
rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setting for im_convert_path or im_identify_path.
CVSS 9.8
CVE-2020-13965 WRITEUP MEDIUM WRITEUP
Roundcube Webmail < 1.3.12 and 1.4.x < 1.4.5 - Stored Cross-Site Scripting via XML Attachment Preview
An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is among the allowed types for a preview.
CVSS 6.1
CVE-2020-16145 WRITEUP MEDIUM WRITEUP
Roundcube Webmail < 1.3.15 and 1.4.8 - Stored Cross-Site Scripting via SVG in HTML Messages
Roundcube Webmail before 1.3.15 and 1.4.8 allows stored XSS in HTML messages during message display via a crafted SVG document. This issue has been fixed in 1.4.8 and 1.3.15.
CVSS 6.1
CVE-2021-44026 WRITEUP CRITICAL WRITEUP
Roundcube < 1.3.17 and 1.4.x < 1.4.12 - SQL Injection via Search Parameters
Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.
CVSS 9.8
CVE-2021-44025 WRITEUP MEDIUM WRITEUP
Roundcube Webmail < 1.3.17 and 1.4.x < 1.4.12 - Cross-Site Scripting via Attachment Filename Extension
Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to XSS in handling an attachment's filename extension when displaying a MIME type warning message.
CVSS 6.1
CVE-2021-44026 WRITEUP CRITICAL WRITEUP
Roundcube < 1.3.17 and 1.4.x < 1.4.12 - SQL Injection via Search Parameters
Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.
CVSS 9.8
CVE-2021-46144 WRITEUP MEDIUM WRITEUP
Roundcube < 1.4.13 and 1.5.x < 1.5.2 - Cross-Site Scripting via Crafted CSS Token Sequences
Roundcube before 1.4.13 and 1.5.x before 1.5.2 allows XSS via an HTML e-mail message with crafted Cascading Style Sheets (CSS) token sequences.
CVSS 6.1
CVE-2022-24953 WRITEUP MEDIUM WRITEUP
Crypt_GPG < 1.6.7 - Argument Injection via GPG Command Options
The Crypt_GPG extension before 1.6.7 for PHP does not prevent additional options in GPG calls, which presents a risk for certain environments and GPG versions.
CVSS 5.3
CVE-2023-43770 WRITEUP MEDIUM WRITEUP
Roundcube <1.4.14, <1.5.4, <1.6.3 - XSS
Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of program/lib/Roundcube/rcube_string_replacer.php behavior.
CVSS 6.1
CVE-2023-5631 WRITEUP MEDIUM WRITEUP
Roundcube Webmail < 1.4.15, 1.5.x < 1.5.5, 1.6.x < 1.6.4 - Stored Cross-Site Scripting via SVG in HTML Email
Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a crafted SVG document because of program/lib/Roundcube/rcube_washtml.php behavior. This could allow a remote attacker to load arbitrary JavaScript code.
CVSS 6.1
CVE-2024-37383 WRITEUP MEDIUM WRITEUP
Roundcube Webmail < 1.5.7 and 1.6.x < 1.6.7 - Cross-Site Scripting via SVG Animate Attributes
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.
CVSS 6.1
CVE-2025-49113 WRITEUP CRITICAL WRITEUP
Roundcube Webmail < 1.5.10 and 1.6.x < 1.6.11 - Authenticated Remote Code Execution via PHP Object Deserialization
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP Object Deserialization.
CVSS 9.9
CVE-2026-26079 WRITEUP MEDIUM WRITEUP
Roundcube Webmail <1.5.13 & <1.6.13 - XSS
Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13 allows Cascading Style Sheets (CSS) injection, e.g., because comments are mishandled.
CVSS 4.7
CVE-2026-26079 WRITEUP MEDIUM WRITEUP
Roundcube Webmail <1.5.13 & <1.6.13 - XSS
Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13 allows Cascading Style Sheets (CSS) injection, e.g., because comments are mishandled.
CVSS 4.7
CVE-2026-26079 WRITEUP MEDIUM WRITEUP
Roundcube Webmail <1.5.13 & <1.6.13 - XSS
Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13 allows Cascading Style Sheets (CSS) injection, e.g., because comments are mishandled.
CVSS 4.7
CVE-2026-26079 WRITEUP MEDIUM WRITEUP
Roundcube Webmail <1.5.13 & <1.6.13 - XSS
Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13 allows Cascading Style Sheets (CSS) injection, e.g., because comments are mishandled.
CVSS 4.7
CVE-2026-35537 WRITEUP LOW WRITEUP
Roundcube Webmail <1.5.14 - Deserialization
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsafe deserialization in the redis/memcache session handler may lead to arbitrary file write operations by unauthenticated attackers via crafted session data.
CVSS 3.7