These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
The CVE record for CVE-2026-75010 was published on 2026-08-17T13:16:55.563Z. The modoboa driver of the password plugin in Roundcube Webmail could leak a Modoboa API authentication token to a user-controlled host via crafted session data. This issue only affects Roundcube instances using the password plugin with its modoboa driver. The vulnerability allows an attacker to potentially access sensitive inform [truncated]
CVE-2026-75007 is a medium-severity vulnerability in Roundcube Webmail before versions 1.6.18 and 1.7.3. The vulnerability allows for LDAP search filter injection via unescaped %u/%fu/%d substitutions, potentially leading to information disclosure or privilege escalation. System administrators and security teams should review the official CVE Program record and NIST NVD detail page for more information. A [truncated]
The CVE-2026-75003 vulnerability affects Roundcube Webmail versions before 1.6.18 and 1.7.3. It is caused by an unclosed url() in a FuncIRI attribute of an SVG image, which could evade remote image blocking. This may lead to information disclosure or privilege escalation. The vulnerability has a CVSS score of 5.8 and is classified as medium-severity. Affected organizations should prioritize updating to ve [truncated]
The CVE-2026-75002 vulnerability in Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3 allows for mail search and LITERAL+ byte-count desynchronization, potentially leading to information disclosure or privilege escalation via IMAP command injection. This issue affects organizations using Roundcube Webmail, particularly those with versions prior to 1.6.18 and 1.7.3. The vulnerability's impact includes [truncated]
The CVE-2026-75000 record involves a medium-severity vulnerability in Roundcube Webmail, affecting versions before 1.6.18 and 1.7.x before 1.7.3. This vulnerability is related to improper HTML/CSS sanitization of the SVG animate 'by' attribute, which may allow remote image blocking bypass. This bypass could potentially lead to information disclosure or privilege escalation. System administrators and secur [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-17T13:16:54.423Z and has not been modified since then. This stored XSS vulnerability in Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3 requires user interaction and can result in limited confidentiality and integrity impacts. The vulnerability is caused by inadequate input validation and out [truncated]
The CVE-2026-74997 issue affects Roundcube Webmail instances using the markasjunk plugin with its cmd_learn driver. Evidence is based on official CVE and NVD records, as well as source references from GitHub commits and releases. To verify, defenders should review the official advisory and GitHub commits for affected scope and vendor guidance. The markasjunk plugin's cmd_learn driver is subject to remote [truncated]
A medium-severity vulnerability was found in Roundcube Webmail, affecting versions before 1.6.17 and 1.7.x before 1.7.2. This issue allows for username spoofing via session data, which could lead to account takeover. The vulnerability has a CVSS score of 6.4 and is classified as MEDIUM. It requires Local access, User interaction, and can result in High impact on Confidentiality and Integrity. System admin [truncated]
CVE-2026-62643 is a vulnerability in Roundcube Webmail before versions 1.6.17 and 1.7.2. The issue is due to insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages, which may lead to Server-Side Request Forgery (SSRF) or Information Disclosure. This vulnerability exists because of insufficient fixes for previous vulnerabilities CVE-2026-35540 and CVE-2026-48843. The affected versio [truncated]
CVE-2026-62642 is a medium-severity vulnerability in Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2. The vulnerability is caused by an infinite loop in the TNEF decoder, which may lead to denial of service upon opening an email with a TNEF attachment. The CVE record was published on 2026-07-14T16:17:04.530Z and was last modified on 2026-07-20T12:55:28.270Z. The vulnerability has a CVSS score of 4. [truncated]
CVE-2026-62641 is a denial of service vulnerability in Roundcube Webmail's TNEF decoder. The issue affects Roundcube Webmail versions before 1.6.17 and 1.7.x before 1.7.2. The vulnerability is due to a crafted compressed-RTF size. Patched versions are available. Users should apply patches to prevent denial of service attacks. This vulnerability has a CVSS score of 4.3 and a severity of MEDIUM.
A stored cross-site scripting (XSS) vulnerability exists in Roundcube Webmail where the subject field of draft messages is not properly sanitized when restored. This affects versions 1.6.x prior to 1.6.16 and 1.7.x prior to 1.7.1. The vulnerability is exploitable in shared mailbox environments where multiple users access the same mailbox, allowing an attacker with mailbox access to inject malicious HTML, [truncated]
## Summary Roundcube Webmail versions 1.6.x prior to 1.6.16 and 1.7.x prior to 1.7.1 contain an insufficient HTML sanitization vulnerability that permits CSS injection via a crafted SVG document containing an animate element with a manipulated attributeName attribute. The flaw stems from inadequate validation of SVG animation attributes during HTML content filtering, allowing attackers to inject arbitrary [truncated]
A session poisoning vulnerability in Roundcube Webmail allows pre-authentication arbitrary file deletion when Redis or Memcache is configured as the session backend. The flaw exists in versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1. An attacker can manipulate session data stored in Redis/Memcache to inject malicious file paths that get processed during session operations, leading to unauthorized file [truncated]
## Summary Roundcube Webmail versions 1.6.x prior to 1.6.16 and 1.7.x prior to 1.7.1 contain a vulnerability in the remote image blocking feature. A crafted CSS `var()` value in an email message can bypass this protection mechanism, potentially enabling information disclosure or access-control bypass. The vulnerability is classified as MEDIUM severity with a CVSS 3.1 score of 6.5. ## Technical Details The [truncated]
A vulnerability in Roundcube Webmail allows remote image blocking bypass for local/private destinations, potentially enabling information disclosure or privilege escalation via crafted text/html email messages. The issue affects versions 1.6.14 through 1.6.16 in the 1.6.x branch and versions prior to 1.7.1 in the 1.7.x branch. The flaw occurs because the application's remote image blocking mechanism fails [truncated]
Roundcube Webmail versions 1.6.x prior to 1.6.16 and 1.7.x prior to 1.7.1 contain an insecure code evaluation vulnerability in the LDAP autovalues configuration option. The autovalues feature allowed dynamic attribute generation through code evaluation, which could be exploited to inject and execute arbitrary code. The vulnerability has been resolved by completely removing support for code evaluation in t [truncated]
Roundcube Webmail versions 1.6.14 through 1.6.16 and 1.7.x before 1.7.1 contain an insufficient CSS sanitization vulnerability in HTML email processing. The flaw allows malicious stylesheet links within email messages to trigger Server-Side Request Forgery (SSRF) or information disclosure when those links reference internal network hosts. This issue represents an incomplete remediation of CVE-2026-35540, [truncated]
A pre-authentication SQL injection vulnerability exists in Roundcube Webmail's virtuser_query plugin. The flaw stems from a preg_replace() backslash escape bypass that allows attackers to manipulate SQL queries before authentication. Affected versions include 1.6.x prior to 1.6.16 and 1.7.x prior to 1.7.1. The vulnerability carries a HIGH severity CVSS 8.1 score with network attack vector, high attack com [truncated]
CVE-2026-35545 is a vulnerability in Roundcube Webmail that allows remote image blocking to be bypassed via SVG content in an e-mail message. This may lead to information disclosure or access-control bypass. The vulnerability has a CVSS score of 5.3 and a severity of MEDIUM. Affected users should apply patches to prevent potential information disclosure or access-control bypass.
A vulnerability was discovered in Roundcube Webmail before versions 1.5.14 and 1.6.14. The issue involves insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages, which may lead to a fixed-position mitigation bypass via the use of !important. This CVE record was published on 2026-04-03T05:16:22.810Z and was last modified on 2026-07-24T21:10:00.143Z. The vulnerability has a CVSS scor [truncated]
CVE-2026-35542 is a vulnerability in Roundcube Webmail that allows bypassing remote image blocking via a crafted background attribute in an email message. This may lead to information disclosure or access-control bypass. The vulnerability exists in Roundcube Webmail before versions 1.5.14 and 1.6.14. An attacker can exploit this vulnerability by sending a specially crafted email message. The CVSS score fo [truncated]
CVE-2026-35541 is a MEDIUM severity vulnerability in Roundcube Webmail before 1.5.14 and 1.6.14. The vulnerability is caused by incorrect password comparison in the password plugin, which could lead to type confusion that allows a password change without knowing the old password. This issue can potentially lead to unauthorized access to user accounts if exploited. Users of Roundcube Webmail before 1.5.14 [truncated]
CVE-2026-35540 is a vulnerability in Roundcube Webmail versions 1.6.0 before 1.6.14. The issue involves insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages, which may lead to Server-Side Request Forgery (SSRF) or Information Disclosure. This vulnerability has a CVSS score of 5.4 and a severity rating of MEDIUM. The vulnerability affects Roundcube Webmail versions from 1.6.0 up t [truncated]
A medium-severity XSS vulnerability was discovered in Roundcube Webmail before versions 1.5.14 and 1.6.14. The issue arises from insufficient HTML attachment sanitization in preview mode, allowing attackers to execute malicious scripts when a victim previews a text/html attachment. This vulnerability has been publicly disclosed and patches are available. Administrators should prioritize patching to preven [truncated]
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsanitized IMAP SEARCH command arguments could lead to IMAP injection or CSRF bypass during mail search. This vulnerability has a CVSS score of 3.1, indicating low severity. Organizations using affected versions should apply patches to prevent potential attacks. The CVE record was published on 2026-04-03T05:16:21.647Z and has not been [truncated]
CVE-2025-68461 is a Roundcube Webmail cross-site scripting (XSS) vulnerability. CISA added it to the Known Exploited Vulnerabilities (KEV) catalog on 2026-02-20, which makes remediation a high priority for any organization that still operates affected Roundcube deployments. The vendor notes referenced in the source corpus point to security updates 1.6.12 and 1.5.12.
CVE-2025-49113 is a Roundcube Webmail deserialization of untrusted data vulnerability that CISA has added to the Known Exploited Vulnerabilities (KEV) catalog, which indicates confirmed exploitation in the wild. The official guidance provided in the source corpus is to apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if m [truncated]
CVE-2024-42009 is a Roundcube Webmail cross-site scripting issue that CISA added to the Known Exploited Vulnerabilities catalog on 2025-06-09. Because it is in KEV, defenders should treat exposure as urgent and follow the vendor’s security-update guidance referenced by CISA. If mitigations are not available, CISA advises discontinuing use of the product.
CVE-2024-37383 is a Cross-Site Scripting (XSS) issue in Roundcube Webmail that CISA added to its Known Exploited Vulnerabilities catalog on 2024-10-24. Because it is in KEV, affected operators should treat it as a priority remediation item and follow vendor guidance or discontinue use if mitigations are unavailable.