Roundcube Vulnerabilities and Affected Products
Vulnerabilities associated with roundcube_webmail.
Products
Clear product- Webmail34 vulnerabilities
- Roundcube Webmail11 vulnerabilities
- roundcube_webmail2 vulnerabilities
- roundcube1 vulnerability
- Roundcubemail1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-37385CRITICAL | Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 on Windows allows command injection via im_convert_path and im_identify_path. NOTE: this issue exists because of an incomplete fix for CVE-2020-12641. CWE-77Jun 7, 2024 | CVSS9.8v3.1 | EPSS1.48% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-37384MEDIUM | Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via list columns from user preferences. CWE-79Jun 7, 2024 | CVSS6.1v3.1 | EPSS0.498% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |