← Back

Roundcube

roundcube

88 CVEs • 3 products

Products (3)

Click to collapse
Toggle
Webmail
webmail
Roundcube
roundcube

CVEs (88)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Debian
OpensuseRoundcube
4Backports Sle
Debian LinuxLeap+1 more
Jun 17, 2026
May 4, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Roundcube Webmail before 1.4.4. There is a cross-site scripting (XSS) vulnerability in rcube_washtml.php because JavaScript code can occur in the CDATA of an HTML message.
2Fedoraproject
Roundcube
2Fedora
Webmail
Jun 17, 2026
Aug 20, 2019
N/A· v4
7.4 HIGH· v3
4.3 MEDIUM· v2
Roundcube Webmail through 1.3.9 mishandles Punycode xn-- domain names, leading to homograph attacks.
3Fedoraproject
OpensuseRoundcube
4Backports Sle
FedoraLeap+1 more
Jun 17, 2026
Apr 7, 2019
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
In Roundcube Webmail before 1.3.10, an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub-parts within a crafted multipart email. The encrypted part(s) can further be hidden using HTML/CSS or A...Show more
In Roundcube Webmail before 1.3.10, an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub-parts within a crafted multipart email. The encrypted part(s) can further be hidden using HTML/CSS or ASCII newline characters. This modified multipart email can be re-sent by the attacker to the intended receiver. If the receiver replies to this (benign looking) email, they unknowingly leak the plaintext of the encrypted message part(s) back to the attacker.Show less
2Debian
Roundcube
2Debian Linux
Webmail
Nov 21, 2024
Nov 12, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
steps/mail/func.inc in Roundcube before 1.3.8 has XSS via crafted use of <svg><style>, as demonstrated by an onload attribute in a BODY element, within an HTML attachment.
1Roundcube
1Webmail
Nov 21, 2024
Nov 12, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Roundcube before 1.3.7 mishandles GnuPG MDC integrity-protection warnings, which makes it easier for attackers to obtain sensitive information, a related issue to CVE-2017-17688. This is associated with plugins/enigma/li...Show more
Roundcube before 1.3.7 mishandles GnuPG MDC integrity-protection warnings, which makes it easier for attackers to obtain sensitive information, a related issue to CVE-2017-17688. This is associated with plugins/enigma/lib/enigma_driver_gnupg.php.Show less
11Apple
BloopEmclient+8 more
11Airmail
EmclientHorde Imp+8 more
Nov 21, 2024
May 16, 2018
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The OpenPGP specification allows a Cipher Feedback Mode (CFB) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL. NOTE: third parties report that this is a problem in applications th...Show more
The OpenPGP specification allows a Cipher Feedback Mode (CFB) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL. NOTE: third parties report that this is a problem in applications that mishandle the Modification Detection Code (MDC) feature or accept an obsolete packet type, not a problem in the OpenPGP specificationShow less
2Debian
Roundcube
2Debian Linux
Webmail
Jun 17, 2026
Apr 7, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In Roundcube from versions 1.2.0 to 1.3.5, with the archive plugin enabled and configured, it's possible to exploit the unsanitized, user-controlled "_uid" parameter (in an archive.php _task=mail&_mbox=INBOX&_action=plug...Show more
In Roundcube from versions 1.2.0 to 1.3.5, with the archive plugin enabled and configured, it's possible to exploit the unsanitized, user-controlled "_uid" parameter (in an archive.php _task=mail&_mbox=INBOX&_action=plugin.move2archive request) to perform an MX (IMAP) injection attack by placing an IMAP command after a %0d%0a sequence. NOTE: this is less easily exploitable in 1.3.4 and later because of a Same Origin Policy protection mechanism.Show less
1Roundcube
1Webmail
Nov 21, 2024
Mar 13, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
roundcube version 1.3.4 and earlier contains an Insecure Permissions vulnerability in enigma plugin that can result in exfiltration of gpg private key. This attack appear to be exploitable via network connectivity.
2Debian
Roundcube
2Debian Linux
Webmail
Apr 21, 2026
Nov 9, 2017
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's filesystem, including configuration files, as exploited in the wild in November 2017...Show more
Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's filesystem, including configuration files, as exploited in the wild in November 2017. The attacker must be able to authenticate at the target system with a valid username/password as the attack requires an active session. The issue is related to file-based attachment plugins and _task=settings&_action=upload-display&_from=timezone requests.Show less
1Roundcube
2Roundcube Webmail
Webmail
May 13, 2026
May 23, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Roundcube Webmail 1.1.x before 1.1.2 allows remote attackers to obtain sensitive information by reading files in the (1) config, (2) temp, or (3) logs directory.
1Roundcube
2Roundcube Webmail
Webmail
May 13, 2026
May 23, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
program/steps/addressbook/photo.inc in Roundcube Webmail before 1.0.6 and 1.1.x before 1.1.2 allows remote authenticated users to read arbitrary files via the _alt parameter when uploading a vCard.
1Roundcube
2Roundcube Webmail
Webmail
May 13, 2026
May 23, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in program/include/rcmail.php in Roundcube Webmail 1.1.x before 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the _mbox parameter to the default URI.
1Roundcube
1Webmail
May 13, 2026
Apr 29, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Roundcube Webmail allows arbitrary password resets by authenticated users. This affects versions before 1.0.11, 1.1.x before 1.1.9, and 1.2.x before 1.2.5. The problem is caused by an improperly restricted exec call in t...Show more
Roundcube Webmail allows arbitrary password resets by authenticated users. This affects versions before 1.0.11, 1.1.x before 1.1.9, and 1.2.x before 1.2.5. The problem is caused by an improperly restricted exec call in the virtualmin and sasl drivers of the password plugin.Show less
2Opensuse
Roundcube
4Leap
OpensuseRoundcube Webmail+1 more
May 13, 2026
Apr 13, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.0.9 and 1.1.x before 1.1.5 allows remote attackers to inject arbitrary web script or HTML via a crafted SVG, a different vulnerability than CVE-2015-...Show more
Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.0.9 and 1.1.x before 1.1.5 allows remote attackers to inject arbitrary web script or HTML via a crafted SVG, a different vulnerability than CVE-2015-8864.Show less
2Opensuse
Roundcube
4Leap
OpensuseRoundcube Webmail+1 more
May 13, 2026
Apr 13, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.0.9 and 1.1.x before 1.1.5 allows remote attackers to inject arbitrary web script or HTML via a crafted SVG, a different vulnerability than CVE-2016-...Show more
Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.0.9 and 1.1.x before 1.1.5 allows remote attackers to inject arbitrary web script or HTML via a crafted SVG, a different vulnerability than CVE-2016-4068.Show less
1Roundcube
1Webmail
May 13, 2026
Mar 12, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
rcube_utils.php in Roundcube before 1.1.8 and 1.2.x before 1.2.4 is susceptible to a cross-site scripting vulnerability via a crafted Cascading Style Sheets (CSS) token sequence within an SVG element.
1Roundcube
1Webmail
May 13, 2026
Jan 30, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Multiple buffer overflows in the DBMail driver in the Password plugin in Roundcube before 1.1.0 allow remote attackers to have unspecified impact via the (1) password or (2) username.
1Roundcube
1Webmail
May 13, 2026
Jan 30, 2017
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
The DBMail driver in the Password plugin in Roundcube before 1.1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the password.
1Roundcube
1Webmail
May 6, 2026
Dec 20, 2016
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.2.0 allows remote attackers to inject arbitrary web script or HTML via the href attribute in an area tag in an e-mail message.
1Roundcube
1Webmail
May 6, 2026
Dec 8, 2016
N/A· v4
7.5 HIGH· v3
6.0 MEDIUM· v2
steps/mail/sendmail.inc in Roundcube before 1.1.7 and 1.2.x before 1.2.3, when no SMTP server is configured and the sendmail program is enabled, does not properly restrict the use of custom envelope-from addresses on the...Show more
steps/mail/sendmail.inc in Roundcube before 1.1.7 and 1.2.x before 1.2.3, when no SMTP server is configured and the sendmail program is enabled, does not properly restrict the use of custom envelope-from addresses on the sendmail command line, which allows remote authenticated users to execute arbitrary code via a modified HTTP request that sends a crafted e-mail message.Show less