Roundcube Vulnerabilities and Affected Products
Vulnerabilities associated with Roundcube Webmail.
Products
Clear product- Webmail34 vulnerabilities
- Roundcube Webmail11 vulnerabilities
- roundcube_webmail2 vulnerabilities
- roundcube1 vulnerability
- Roundcubemail1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-68461HIGH | RoundCube Webmail Cross-site Scripting VulnerabilityRoundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document. CWE-79Dec 18, 2025 | CVSS7.2v3.1 | EPSS20.5% | PoCs2 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-49113CRITICAL | Roundcube Webmail Vulnerable to Authenticated RCE via PHP Object DeserializationRoundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP Object Deserialization. | CVSS9.9v3.1 | EPSS97.7% | PoCs24 | SignalsListed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2024-42009CRITICAL | RoundCube Webmail Cross-Site Scripting VulnerabilityA Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a crafted e-mail message that abuses a Desanitization issue in message_body() in program/actions/mail/show.php. | CVSS9.3v3.1 | EPSS79.6% | PoCs7 | SignalsListed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2024-37383MEDIUM | RoundCube Webmail Cross-Site Scripting (XSS) VulnerabilityRoundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes. CWE-79Jun 7, 2024 | CVSS6.1v3.1 | EPSS73.3% | PoCs4 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-5631MEDIUM | Stored XSS vulnerability in RoundcubeRoundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a crafted SVG document because of program/lib/Roundcube/rcube_washtml.php behavior. This could allow a remote attacker to load arbitrary JavaScript code. CWE-79Oct 18, 2023 | CVSS6.1v3.1 | EPSS75.9% | PoCs0 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-43770MEDIUM | Roundcube Webmail Persistent Cross-Site Scripting (XSS) VulnerabilityRoundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of program/lib/Roundcube/rcube_string_replacer.php behavior. CWE-79Sep 22, 2023 | CVSS6.1v3.1 | EPSS58.5% | PoCs3 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-44026CRITICAL | Roundcube Webmail SQL Injection VulnerabilityRoundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params. CWE-89Nov 19, 2021 | CVSS9.8v3.1 | EPSS42.8% | PoCs2 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-35730MEDIUM | Roundcube Webmail Cross-Site Scripting (XSS) VulnerabilityAn XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attacker can send a plain text e-mail message, with JavaScript in a link reference element that is mishandled by linkref_addindex in rcube_string_replacer.php. CWE-79Dec 28, 2020 | CVSS6.1v3.1 | EPSS32.7% | PoCs1 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-13965MEDIUM | Roundcube Webmail Cross-Site Scripting (XSS) VulnerabilityAn issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is among the allowed types for a preview. | CVSS6.3v3.1 | EPSS76.6% | PoCs1 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-12641CRITICAL | Roundcube Webmail Remote Code Execution Vulnerabilityrcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setting for im_convert_path or im_identify_path. | CVSS9.8v3.1 | EPSS84.5% | PoCs2 | SignalsListed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2017-16651HIGH | Roundcube Webmail File Disclosure VulnerabilityRoundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's filesystem, including configuration files, as exploited in the wild in November 2017. The attacker must be able to authenticate at the target system with a valid username/password as the attack requires an active session. The issue is related to file-based attachment plugins and _task=settings&_action=upload-display&_from=timezone requests. CWE-552Nov 9, 2017 | CVSS7.8v3.1 | EPSS36.9% | PoCs3 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |