PatchSiren

Roundcube CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Roundcube CVE published 2026-07-14

CVE-2026-62644

A medium-severity vulnerability was found in Roundcube Webmail, affecting versions before 1.6.17 and 1.7.x before 1.7.2. This issue allows for username spoofing via session data, which could lead to account takeover. The vulnerability has a CVSS score of 6.4 and is classified as MEDIUM. It requires Local access, User interaction, and can result in High impact on Confidentiality and Integrity. System admin [truncated]

HIGH Roundcube CVE published 2026-07-14

CVE-2026-62643

CVE-2026-62643 is a vulnerability in Roundcube Webmail before versions 1.6.17 and 1.7.2. The issue is due to insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages, which may lead to Server-Side Request Forgery (SSRF) or Information Disclosure. This vulnerability exists because of insufficient fixes for previous vulnerabilities CVE-2026-35540 and CVE-2026-48843. The affected versio [truncated]

MEDIUM Roundcube CVE published 2026-07-14

CVE-2026-62642

CVE-2026-62642 is a medium-severity vulnerability in Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2. The vulnerability is caused by an infinite loop in the TNEF decoder, which may lead to denial of service upon opening an email with a TNEF attachment. The CVE record was published on 2026-07-14T16:17:04.530Z and was last modified on 2026-07-20T12:55:28.270Z. The vulnerability has a CVSS score of 4. [truncated]

MEDIUM Roundcube CVE published 2026-07-14

CVE-2026-62641

CVE-2026-62641 is a denial of service vulnerability in Roundcube Webmail's TNEF decoder. The issue affects Roundcube Webmail versions before 1.6.17 and 1.7.x before 1.7.2. The vulnerability is due to a crafted compressed-RTF size. Patched versions are available. Users should apply patches to prevent denial of service attacks. This vulnerability has a CVSS score of 4.3 and a severity of MEDIUM.

MEDIUM Roundcube CVE published 2026-05-25

CVE-2026-48849

A stored cross-site scripting (XSS) vulnerability exists in Roundcube Webmail where the subject field of draft messages is not properly sanitized when restored. This affects versions 1.6.x prior to 1.6.16 and 1.7.x prior to 1.7.1. The vulnerability is exploitable in shared mailbox environments where multiple users access the same mailbox, allowing an attacker with mailbox access to inject malicious HTML, [truncated]

HIGH Roundcube CVE published 2026-05-25

CVE-2026-48848

## Summary Roundcube Webmail versions 1.6.x prior to 1.6.16 and 1.7.x prior to 1.7.1 contain an insufficient HTML sanitization vulnerability that permits CSS injection via a crafted SVG document containing an animate element with a manipulated attributeName attribute. The flaw stems from inadequate validation of SVG animation attributes during HTML content filtering, allowing attackers to inject arbitrary [truncated]

LOW Roundcube CVE published 2026-05-25

CVE-2026-48847

A session poisoning vulnerability in Roundcube Webmail allows pre-authentication arbitrary file deletion when Redis or Memcache is configured as the session backend. The flaw exists in versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1. An attacker can manipulate session data stored in Redis/Memcache to inject malicious file paths that get processed during session operations, leading to unauthorized file [truncated]

MEDIUM Roundcube CVE published 2026-05-25

CVE-2026-48846

## Summary Roundcube Webmail versions 1.6.x prior to 1.6.16 and 1.7.x prior to 1.7.1 contain a vulnerability in the remote image blocking feature. A crafted CSS `var()` value in an email message can bypass this protection mechanism, potentially enabling information disclosure or access-control bypass. The vulnerability is classified as MEDIUM severity with a CVSS 3.1 score of 6.5. ## Technical Details The [truncated]

MEDIUM Roundcube CVE published 2026-05-25

CVE-2026-48845

A vulnerability in Roundcube Webmail allows remote image blocking bypass for local/private destinations, potentially enabling information disclosure or privilege escalation via crafted text/html email messages. The issue affects versions 1.6.14 through 1.6.16 in the 1.6.x branch and versions prior to 1.7.1 in the 1.7.x branch. The flaw occurs because the application's remote image blocking mechanism fails [truncated]

HIGH Roundcube CVE published 2026-05-25

CVE-2026-48844

Roundcube Webmail versions 1.6.x prior to 1.6.16 and 1.7.x prior to 1.7.1 contain an insecure code evaluation vulnerability in the LDAP autovalues configuration option. The autovalues feature allowed dynamic attribute generation through code evaluation, which could be exploited to inject and execute arbitrary code. The vulnerability has been resolved by completely removing support for code evaluation in t [truncated]

HIGH Roundcube CVE published 2026-05-25

CVE-2026-48843

Roundcube Webmail versions 1.6.14 through 1.6.16 and 1.7.x before 1.7.1 contain an insufficient CSS sanitization vulnerability in HTML email processing. The flaw allows malicious stylesheet links within email messages to trigger Server-Side Request Forgery (SSRF) or information disclosure when those links reference internal network hosts. This issue represents an incomplete remediation of CVE-2026-35540, [truncated]

HIGH Roundcube CVE published 2026-05-25

CVE-2026-48842

A pre-authentication SQL injection vulnerability exists in Roundcube Webmail's virtuser_query plugin. The flaw stems from a preg_replace() backslash escape bypass that allows attackers to manipulate SQL queries before authentication. Affected versions include 1.6.x prior to 1.6.16 and 1.7.x prior to 1.7.1. The vulnerability carries a HIGH severity CVSS 8.1 score with network attack vector, high attack com [truncated]

MEDIUM Roundcube CVE published 2026-04-03

CVE-2026-35545

CVE-2026-35545 is a vulnerability in Roundcube Webmail that allows remote image blocking to be bypassed via SVG content in an e-mail message. This may lead to information disclosure or access-control bypass. The vulnerability has a CVSS score of 5.3 and a severity of MEDIUM. Affected users should apply patches to prevent potential information disclosure or access-control bypass.

MEDIUM Roundcube CVE published 2026-04-03

CVE-2026-35544

A vulnerability was discovered in Roundcube Webmail before versions 1.5.14 and 1.6.14. The issue involves insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages, which may lead to a fixed-position mitigation bypass via the use of !important. This CVE record was published on 2026-04-03T05:16:22.810Z and was last modified on 2026-07-24T21:10:00.143Z. The vulnerability has a CVSS scor [truncated]

MEDIUM Roundcube CVE published 2026-04-03

CVE-2026-35542

CVE-2026-35542 is a vulnerability in Roundcube Webmail that allows bypassing remote image blocking via a crafted background attribute in an email message. This may lead to information disclosure or access-control bypass. The vulnerability exists in Roundcube Webmail before versions 1.5.14 and 1.6.14. An attacker can exploit this vulnerability by sending a specially crafted email message. The CVSS score fo [truncated]

MEDIUM Roundcube CVE published 2026-04-03

CVE-2026-35541

CVE-2026-35541 is a MEDIUM severity vulnerability in Roundcube Webmail before 1.5.14 and 1.6.14. The vulnerability is caused by incorrect password comparison in the password plugin, which could lead to type confusion that allows a password change without knowing the old password. This issue can potentially lead to unauthorized access to user accounts if exploited. Users of Roundcube Webmail before 1.5.14 [truncated]

MEDIUM Roundcube CVE published 2026-04-03

CVE-2026-35540

CVE-2026-35540 is a vulnerability in Roundcube Webmail versions 1.6.0 before 1.6.14. The issue involves insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages, which may lead to Server-Side Request Forgery (SSRF) or Information Disclosure. This vulnerability has a CVSS score of 5.4 and a severity rating of MEDIUM. The vulnerability affects Roundcube Webmail versions from 1.6.0 up t [truncated]

MEDIUM Roundcube CVE published 2026-04-03

CVE-2026-35539

A medium-severity XSS vulnerability was discovered in Roundcube Webmail before versions 1.5.14 and 1.6.14. The issue arises from insufficient HTML attachment sanitization in preview mode, allowing attackers to execute malicious scripts when a victim previews a text/html attachment. This vulnerability has been publicly disclosed and patches are available. Administrators should prioritize patching to preven [truncated]

LOW Roundcube CVE published 2026-04-03

CVE-2026-35538

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsanitized IMAP SEARCH command arguments could lead to IMAP injection or CSRF bypass during mail search. This vulnerability has a CVSS score of 3.1, indicating low severity. Organizations using affected versions should apply patches to prevent potential attacks. The CVE record was published on 2026-04-03T05:16:21.647Z and has not been [truncated]

Known exploited Roundcube CVE published 2026-02-20

CVE-2025-68461

CVE-2025-68461 is a Roundcube Webmail cross-site scripting (XSS) vulnerability. CISA added it to the Known Exploited Vulnerabilities (KEV) catalog on 2026-02-20, which makes remediation a high priority for any organization that still operates affected Roundcube deployments. The vendor notes referenced in the source corpus point to security updates 1.6.12 and 1.5.12.

Known exploited Roundcube CVE published 2026-02-20

CVE-2025-49113

CVE-2025-49113 is a Roundcube Webmail deserialization of untrusted data vulnerability that CISA has added to the Known Exploited Vulnerabilities (KEV) catalog, which indicates confirmed exploitation in the wild. The official guidance provided in the source corpus is to apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if m [truncated]

Known exploited Roundcube CVE published 2025-06-09

CVE-2024-42009

CVE-2024-42009 is a Roundcube Webmail cross-site scripting issue that CISA added to the Known Exploited Vulnerabilities catalog on 2025-06-09. Because it is in KEV, defenders should treat exposure as urgent and follow the vendor’s security-update guidance referenced by CISA. If mitigations are not available, CISA advises discontinuing use of the product.

Known exploited Roundcube CVE published 2024-10-24

CVE-2024-37383

CVE-2024-37383 is a Cross-Site Scripting (XSS) issue in Roundcube Webmail that CISA added to its Known Exploited Vulnerabilities catalog on 2024-10-24. Because it is in KEV, affected operators should treat it as a priority remediation item and follow vendor guidance or discontinue use if mitigations are unavailable.

Known exploited Roundcube CVE published 2024-06-26

CVE-2020-13965

CVE-2020-13965 is a cross-site scripting (XSS) issue affecting Roundcube Webmail. CISA added it to the Known Exploited Vulnerabilities catalog on 2024-06-26, which makes it a high-priority remediation item for anyone running Roundcube Webmail. Defenders should confirm whether any Roundcube instances are in use, apply the vendor's security guidance referenced by CISA, and if mitigations cannot be applied s [truncated]

Known exploited Roundcube CVE published 2024-02-12

CVE-2023-43770

CVE-2023-43770 is a persistent cross-site scripting (XSS) issue in Roundcube Webmail that CISA added to the Known Exploited Vulnerabilities catalog on 2024-02-12. That KEV listing is the strongest signal in the supplied corpus that this issue should be treated as actively exploited or otherwise operationally important. For defenders, the practical takeaway is straightforward: prioritize remediation on any [truncated]

Known exploited Roundcube CVE published 2023-10-26

CVE-2023-5631

CVE-2023-5631 is a persistent cross-site scripting (XSS) vulnerability in Roundcube Webmail. CISA added it to the Known Exploited Vulnerabilities catalog on 2023-10-26, so defenders should treat it as actively exploited and prioritize remediation before the 2023-11-16 due date. Roundcube’s vendor security-update notices referenced in the source corpus were published on 2023-10-16, and CISA directs organiz [truncated]

Known exploited Roundcube CVE published 2023-06-22

CVE-2021-44026

CVE-2021-44026 is a Roundcube Webmail SQL injection vulnerability that CISA placed in its Known Exploited Vulnerabilities catalog on 2023-06-22. The official remediation note points to Roundcube security updates 1.4.12 and 1.3.17 released by the vendor, so organizations running Roundcube should apply the vendor guidance promptly and confirm all exposed instances are updated.

Known exploited Roundcube CVE published 2023-06-22

CVE-2020-35730

CVE-2020-35730 is a cross-site scripting (XSS) vulnerability in Roundcube Webmail. It is notable because CISA added it to the Known Exploited Vulnerabilities catalog on 2023-06-22, which indicates it is considered actively exploited and should be prioritized for remediation. The official guidance in the KEV record is to apply updates per vendor instructions.

Known exploited Roundcube CVE published 2023-06-22

CVE-2020-12641

CVE-2020-12641 is a Roundcube Webmail remote code execution vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2023-06-22, with a remediation due date of 2023-07-13. Based on the supplied official sources, the main defensive takeaway is clear: treat this as a high-priority patching issue and follow the vendor’s update instructions.

Known exploited Roundcube CVE published 2021-11-03

CVE-2017-16651

CVE-2017-16651 is a Roundcube Webmail file disclosure vulnerability that CISA has listed in the Known Exploited Vulnerabilities catalog. That KEV designation means it should be treated as actively relevant for defense and remediation planning, even though the supplied official sources do not provide deeper technical details here.

HIGH Roundcube CVE published 2017-01-30

CVE-2015-2181

CVE-2015-2181 affects Roundcube webmail before 1.1.0 in the Password plugin’s DBMail driver. The issue is described as multiple buffer overflows triggered through the username or password fields, with remote attackers able to cause unspecified impact. NVD rates the vulnerability HIGH with a CVSS 3.0 score of 8.8, reflecting network reachability, low privileges, no user interaction, and high confidentialit [truncated]

HIGH Roundcube CVE published 2017-01-30

CVE-2015-2180

CVE-2015-2180 affects Roundcube webmail before 1.1.0, specifically the Password plugin’s DBMail driver. The CVE description and NVD record state that shell metacharacters in the password can be used to execute arbitrary commands. NVD rates the issue as network-accessible with low attack complexity, low privileges required, no user interaction, and high impact to confidentiality, integrity, and availability.