Showing 11 vulnerabilities on this page for Roundcube Webmail

Signals CISA KEV Ransomware Nuclei
Roundcube vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

RoundCube Webmail Cross-site Scripting Vulnerability

Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document.

CWE-79Dec 18, 2025
CVSS7.2v3.1EPSS20.5%PoCs2SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Roundcube Webmail Vulnerable to Authenticated RCE via PHP Object Deserialization

Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP Object Deserialization.

CWE-502Jun 2, 20251 related artifact
CVSS9.9v3.1EPSS97.7%PoCs24SignalsListed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

RoundCube Webmail Cross-Site Scripting Vulnerability

A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a crafted e-mail message that abuses a Desanitization issue in message_body() in program/actions/mail/show.php.

CWE-79Aug 5, 20241 related artifact
CVSS9.3v3.1EPSS79.6%PoCs7SignalsListed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

RoundCube Webmail Cross-Site Scripting (XSS) Vulnerability

Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.

CWE-79Jun 7, 2024
CVSS6.1v3.1EPSS73.3%PoCs4SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Stored XSS vulnerability in Roundcube

Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a crafted SVG document because of program/lib/Roundcube/rcube_washtml.php behavior. This could allow a remote attacker to load arbitrary JavaScript code.

CWE-79Oct 18, 2023
CVSS6.1v3.1EPSS75.9%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability

Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of program/lib/Roundcube/rcube_string_replacer.php behavior.

CWE-79Sep 22, 2023
CVSS6.1v3.1EPSS58.5%PoCs3SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Roundcube Webmail SQL Injection Vulnerability

Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.

CWE-89Nov 19, 2021
CVSS9.8v3.1EPSS42.8%PoCs2SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Roundcube Webmail Cross-Site Scripting (XSS) Vulnerability

An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attacker can send a plain text e-mail message, with JavaScript in a link reference element that is mishandled by linkref_addindex in rcube_string_replacer.php.

CWE-79Dec 28, 2020
CVSS6.1v3.1EPSS32.7%PoCs1SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Roundcube Webmail Cross-Site Scripting (XSS) Vulnerability

An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is among the allowed types for a preview.

CWE-79CWE-80Jun 9, 2020
CVSS6.3v3.1EPSS76.6%PoCs1SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Roundcube Webmail Remote Code Execution Vulnerability

rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setting for im_convert_path or im_identify_path.

CWE-78CWE-88May 4, 20201 related artifact
CVSS9.8v3.1EPSS84.5%PoCs2SignalsListed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Roundcube Webmail File Disclosure Vulnerability

Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's filesystem, including configuration files, as exploited in the wild in November 2017. The attacker must be able to authenticate at the target system with a valid username/password as the attack requires an active session. The issue is related to file-based attachment plugins and _task=settings&_action=upload-display&_from=timezone requests.

CWE-552Nov 9, 2017
CVSS7.8v3.1EPSS36.9%PoCs3SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX