Aleksander Machniak
80 exploits
Active since Aug 2012
Roundcube Webmail 1.6.0-1.6.13 - Server-Side Request Forgery via CSS Stylesheet Links
CVSS 5.4
Roundcube Webmail <1.5.14 - Auth Bypass
CVSS 4.2
Roundcube Webmail <1.5.14, 1.6.0-1.6.14, 1.7-beta-1.7-rc5 - Information Disclosure via Background Attribute Bypass
CVSS 5.3
Roundcube Webmail < 1.5.14, 1.6.0-1.6.14, 1.7-beta-1.7-rc5 - Information Disclosure via SVG Animate Attribute Bypass
CVSS 5.3
Roundcube Webmail <1.5.14 - CSS Sanitization Bypass
CVSS 5.3
Roundcube Webmail < 1.5.15, 1.6.0-1.6.15, 1.7-beta-1.7-rc5 - Information Disclosure via SVG Animate Element Bypass
CVSS 5.3
Roundcube Webmail <1.5.14 - Deserialization
CVSS 3.7
Roundcube Webmail < 1.5.14, 1.6.0-1.6.14, 1.7-beta-1.7-rc5 - IMAP Injection via Search Command Arguments
CVSS 3.1
Roundcube Webmail <1.5.14, 1.6.0-1.6.14, 1.7-beta-1.7-rc5 - Stored Cross-Site Scripting via HTML Attachment Preview
CVSS 6.1
Roundcube Webmail 1.6.0-1.6.13 - Server-Side Request Forgery via CSS Stylesheet Links
CVSS 5.4
Roundcube Webmail <1.5.14 - Auth Bypass
CVSS 4.2
Roundcube Webmail <1.5.14, 1.6.0-1.6.14, 1.7-beta-1.7-rc5 - Information Disclosure via Background Attribute Bypass
CVSS 5.3
Roundcube Webmail < 1.5.14, 1.6.0-1.6.14, 1.7-beta-1.7-rc5 - Information Disclosure via SVG Animate Attribute Bypass
CVSS 5.3
Roundcube Webmail <1.5.14 - CSS Sanitization Bypass
CVSS 5.3
Roundcube Webmail < 1.5.15, 1.6.0-1.6.15, 1.7-beta-1.7-rc5 - Information Disclosure via SVG Animate Element Bypass
CVSS 5.3
Roundcube Webmail < 0.8.5 - Cross-Site Scripting via Data or VBScript Link
Roundcube Webmail 1.1.x - Cross-Site Scripting via _mbox Parameter
CVSS 6.1
Roundcube Webmail <1.0.6, <1.1.2 - Info Disclosure
CVSS 6.5
Roundcube Webmail < 1.4.4 - Cross-Site Request Forgery via Logout POST Request
CVSS 6.5
Roundcube Webmail < 1.3.12 and 1.4.x < 1.4.5 - Cross-Site Scripting via Username Template Object
CVSS 6.1
Roundcube Webmail < 1.2.11, 1.3.x < 1.3.14, 1.4.x < 1.4.7 - Stored Cross-Site Scripting via HTML Email xmlns Attribute
CVSS 6.1
Roundcube Webmail < 1.3.15 and 1.4.8 - Stored Cross-Site Scripting via SVG in HTML Messages
CVSS 6.1
Roundcube Webmail < 1.4.11 - Cross-Site Scripting via CSS Token Sequences in HTML Email Renderer
CVSS 5.4
Roundcube < 1.4.13 and 1.5.x < 1.5.2 - Cross-Site Scripting via Crafted CSS Token Sequences
CVSS 6.1
Roundcube Webmail 1.5.0-1.5.5 and 1.6.0-1.6.4 - Cross-Site Scripting via Content-Type or Content-Disposition Header
CVSS 6.1