PatchSiren

Roundcube CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Roundcube CVE published 2026-08-17

CVE-2026-75010

The CVE record for CVE-2026-75010 was published on 2026-08-17T13:16:55.563Z. The modoboa driver of the password plugin in Roundcube Webmail could leak a Modoboa API authentication token to a user-controlled host via crafted session data. This issue only affects Roundcube instances using the password plugin with its modoboa driver. The vulnerability allows an attacker to potentially access sensitive inform [truncated]

MEDIUM Roundcube CVE published 2026-08-17

CVE-2026-75007

CVE-2026-75007 is a medium-severity vulnerability in Roundcube Webmail before versions 1.6.18 and 1.7.3. The vulnerability allows for LDAP search filter injection via unescaped %u/%fu/%d substitutions, potentially leading to information disclosure or privilege escalation. System administrators and security teams should review the official CVE Program record and NIST NVD detail page for more information. A [truncated]

MEDIUM Roundcube CVE published 2026-08-17

CVE-2026-75003

The CVE-2026-75003 vulnerability affects Roundcube Webmail versions before 1.6.18 and 1.7.3. It is caused by an unclosed url() in a FuncIRI attribute of an SVG image, which could evade remote image blocking. This may lead to information disclosure or privilege escalation. The vulnerability has a CVSS score of 5.8 and is classified as medium-severity. Affected organizations should prioritize updating to ve [truncated]

HIGH Roundcube CVE published 2026-08-17

CVE-2026-75002

The CVE-2026-75002 vulnerability in Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3 allows for mail search and LITERAL+ byte-count desynchronization, potentially leading to information disclosure or privilege escalation via IMAP command injection. This issue affects organizations using Roundcube Webmail, particularly those with versions prior to 1.6.18 and 1.7.3. The vulnerability's impact includes [truncated]

MEDIUM Roundcube CVE published 2026-08-17

CVE-2026-75000

The CVE-2026-75000 record involves a medium-severity vulnerability in Roundcube Webmail, affecting versions before 1.6.18 and 1.7.x before 1.7.3. This vulnerability is related to improper HTML/CSS sanitization of the SVG animate 'by' attribute, which may allow remote image blocking bypass. This bypass could potentially lead to information disclosure or privilege escalation. System administrators and secur [truncated]

MEDIUM Roundcube CVE published 2026-08-17

CVE-2026-74999

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-17T13:16:54.423Z and has not been modified since then. This stored XSS vulnerability in Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3 requires user interaction and can result in limited confidentiality and integrity impacts. The vulnerability is caused by inadequate input validation and out [truncated]

HIGH Roundcube CVE published 2026-08-17

CVE-2026-74997

The CVE-2026-74997 issue affects Roundcube Webmail instances using the markasjunk plugin with its cmd_learn driver. Evidence is based on official CVE and NVD records, as well as source references from GitHub commits and releases. To verify, defenders should review the official advisory and GitHub commits for affected scope and vendor guidance. The markasjunk plugin's cmd_learn driver is subject to remote [truncated]

MEDIUM Roundcube CVE published 2026-07-14

CVE-2026-62644

A medium-severity vulnerability was found in Roundcube Webmail, affecting versions before 1.6.17 and 1.7.x before 1.7.2. This issue allows for username spoofing via session data, which could lead to account takeover. The vulnerability has a CVSS score of 6.4 and is classified as MEDIUM. It requires Local access, User interaction, and can result in High impact on Confidentiality and Integrity. System admin [truncated]

HIGH Roundcube CVE published 2026-07-14

CVE-2026-62643

CVE-2026-62643 is a vulnerability in Roundcube Webmail before versions 1.6.17 and 1.7.2. The issue is due to insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages, which may lead to Server-Side Request Forgery (SSRF) or Information Disclosure. This vulnerability exists because of insufficient fixes for previous vulnerabilities CVE-2026-35540 and CVE-2026-48843. The affected versio [truncated]

MEDIUM Roundcube CVE published 2026-07-14

CVE-2026-62642

CVE-2026-62642 is a medium-severity vulnerability in Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2. The vulnerability is caused by an infinite loop in the TNEF decoder, which may lead to denial of service upon opening an email with a TNEF attachment. The CVE record was published on 2026-07-14T16:17:04.530Z and was last modified on 2026-07-20T12:55:28.270Z. The vulnerability has a CVSS score of 4. [truncated]

MEDIUM Roundcube CVE published 2026-07-14

CVE-2026-62641

CVE-2026-62641 is a denial of service vulnerability in Roundcube Webmail's TNEF decoder. The issue affects Roundcube Webmail versions before 1.6.17 and 1.7.x before 1.7.2. The vulnerability is due to a crafted compressed-RTF size. Patched versions are available. Users should apply patches to prevent denial of service attacks. This vulnerability has a CVSS score of 4.3 and a severity of MEDIUM.

MEDIUM Roundcube CVE published 2026-05-25

CVE-2026-48849

A stored cross-site scripting (XSS) vulnerability exists in Roundcube Webmail where the subject field of draft messages is not properly sanitized when restored. This affects versions 1.6.x prior to 1.6.16 and 1.7.x prior to 1.7.1. The vulnerability is exploitable in shared mailbox environments where multiple users access the same mailbox, allowing an attacker with mailbox access to inject malicious HTML, [truncated]

HIGH Roundcube CVE published 2026-05-25

CVE-2026-48848

## Summary Roundcube Webmail versions 1.6.x prior to 1.6.16 and 1.7.x prior to 1.7.1 contain an insufficient HTML sanitization vulnerability that permits CSS injection via a crafted SVG document containing an animate element with a manipulated attributeName attribute. The flaw stems from inadequate validation of SVG animation attributes during HTML content filtering, allowing attackers to inject arbitrary [truncated]

LOW Roundcube CVE published 2026-05-25

CVE-2026-48847

A session poisoning vulnerability in Roundcube Webmail allows pre-authentication arbitrary file deletion when Redis or Memcache is configured as the session backend. The flaw exists in versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1. An attacker can manipulate session data stored in Redis/Memcache to inject malicious file paths that get processed during session operations, leading to unauthorized file [truncated]

MEDIUM Roundcube CVE published 2026-05-25

CVE-2026-48846

## Summary Roundcube Webmail versions 1.6.x prior to 1.6.16 and 1.7.x prior to 1.7.1 contain a vulnerability in the remote image blocking feature. A crafted CSS `var()` value in an email message can bypass this protection mechanism, potentially enabling information disclosure or access-control bypass. The vulnerability is classified as MEDIUM severity with a CVSS 3.1 score of 6.5. ## Technical Details The [truncated]

MEDIUM Roundcube CVE published 2026-05-25

CVE-2026-48845

A vulnerability in Roundcube Webmail allows remote image blocking bypass for local/private destinations, potentially enabling information disclosure or privilege escalation via crafted text/html email messages. The issue affects versions 1.6.14 through 1.6.16 in the 1.6.x branch and versions prior to 1.7.1 in the 1.7.x branch. The flaw occurs because the application's remote image blocking mechanism fails [truncated]

HIGH Roundcube CVE published 2026-05-25

CVE-2026-48844

Roundcube Webmail versions 1.6.x prior to 1.6.16 and 1.7.x prior to 1.7.1 contain an insecure code evaluation vulnerability in the LDAP autovalues configuration option. The autovalues feature allowed dynamic attribute generation through code evaluation, which could be exploited to inject and execute arbitrary code. The vulnerability has been resolved by completely removing support for code evaluation in t [truncated]

HIGH Roundcube CVE published 2026-05-25

CVE-2026-48843

Roundcube Webmail versions 1.6.14 through 1.6.16 and 1.7.x before 1.7.1 contain an insufficient CSS sanitization vulnerability in HTML email processing. The flaw allows malicious stylesheet links within email messages to trigger Server-Side Request Forgery (SSRF) or information disclosure when those links reference internal network hosts. This issue represents an incomplete remediation of CVE-2026-35540, [truncated]

HIGH Roundcube CVE published 2026-05-25

CVE-2026-48842

A pre-authentication SQL injection vulnerability exists in Roundcube Webmail's virtuser_query plugin. The flaw stems from a preg_replace() backslash escape bypass that allows attackers to manipulate SQL queries before authentication. Affected versions include 1.6.x prior to 1.6.16 and 1.7.x prior to 1.7.1. The vulnerability carries a HIGH severity CVSS 8.1 score with network attack vector, high attack com [truncated]

MEDIUM Roundcube CVE published 2026-04-03

CVE-2026-35545

CVE-2026-35545 is a vulnerability in Roundcube Webmail that allows remote image blocking to be bypassed via SVG content in an e-mail message. This may lead to information disclosure or access-control bypass. The vulnerability has a CVSS score of 5.3 and a severity of MEDIUM. Affected users should apply patches to prevent potential information disclosure or access-control bypass.

MEDIUM Roundcube CVE published 2026-04-03

CVE-2026-35544

A vulnerability was discovered in Roundcube Webmail before versions 1.5.14 and 1.6.14. The issue involves insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages, which may lead to a fixed-position mitigation bypass via the use of !important. This CVE record was published on 2026-04-03T05:16:22.810Z and was last modified on 2026-07-24T21:10:00.143Z. The vulnerability has a CVSS scor [truncated]

MEDIUM Roundcube CVE published 2026-04-03

CVE-2026-35542

CVE-2026-35542 is a vulnerability in Roundcube Webmail that allows bypassing remote image blocking via a crafted background attribute in an email message. This may lead to information disclosure or access-control bypass. The vulnerability exists in Roundcube Webmail before versions 1.5.14 and 1.6.14. An attacker can exploit this vulnerability by sending a specially crafted email message. The CVSS score fo [truncated]

MEDIUM Roundcube CVE published 2026-04-03

CVE-2026-35541

CVE-2026-35541 is a MEDIUM severity vulnerability in Roundcube Webmail before 1.5.14 and 1.6.14. The vulnerability is caused by incorrect password comparison in the password plugin, which could lead to type confusion that allows a password change without knowing the old password. This issue can potentially lead to unauthorized access to user accounts if exploited. Users of Roundcube Webmail before 1.5.14 [truncated]

MEDIUM Roundcube CVE published 2026-04-03

CVE-2026-35540

CVE-2026-35540 is a vulnerability in Roundcube Webmail versions 1.6.0 before 1.6.14. The issue involves insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages, which may lead to Server-Side Request Forgery (SSRF) or Information Disclosure. This vulnerability has a CVSS score of 5.4 and a severity rating of MEDIUM. The vulnerability affects Roundcube Webmail versions from 1.6.0 up t [truncated]

MEDIUM Roundcube CVE published 2026-04-03

CVE-2026-35539

A medium-severity XSS vulnerability was discovered in Roundcube Webmail before versions 1.5.14 and 1.6.14. The issue arises from insufficient HTML attachment sanitization in preview mode, allowing attackers to execute malicious scripts when a victim previews a text/html attachment. This vulnerability has been publicly disclosed and patches are available. Administrators should prioritize patching to preven [truncated]

LOW Roundcube CVE published 2026-04-03

CVE-2026-35538

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsanitized IMAP SEARCH command arguments could lead to IMAP injection or CSRF bypass during mail search. This vulnerability has a CVSS score of 3.1, indicating low severity. Organizations using affected versions should apply patches to prevent potential attacks. The CVE record was published on 2026-04-03T05:16:21.647Z and has not been [truncated]

Known exploited Roundcube CVE published 2026-02-20

CVE-2025-68461

CVE-2025-68461 is a Roundcube Webmail cross-site scripting (XSS) vulnerability. CISA added it to the Known Exploited Vulnerabilities (KEV) catalog on 2026-02-20, which makes remediation a high priority for any organization that still operates affected Roundcube deployments. The vendor notes referenced in the source corpus point to security updates 1.6.12 and 1.5.12.

Known exploited Roundcube CVE published 2026-02-20

CVE-2025-49113

CVE-2025-49113 is a Roundcube Webmail deserialization of untrusted data vulnerability that CISA has added to the Known Exploited Vulnerabilities (KEV) catalog, which indicates confirmed exploitation in the wild. The official guidance provided in the source corpus is to apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if m [truncated]

Known exploited Roundcube CVE published 2025-06-09

CVE-2024-42009

CVE-2024-42009 is a Roundcube Webmail cross-site scripting issue that CISA added to the Known Exploited Vulnerabilities catalog on 2025-06-09. Because it is in KEV, defenders should treat exposure as urgent and follow the vendor’s security-update guidance referenced by CISA. If mitigations are not available, CISA advises discontinuing use of the product.

Known exploited Roundcube CVE published 2024-10-24

CVE-2024-37383

CVE-2024-37383 is a Cross-Site Scripting (XSS) issue in Roundcube Webmail that CISA added to its Known Exploited Vulnerabilities catalog on 2024-10-24. Because it is in KEV, affected operators should treat it as a priority remediation item and follow vendor guidance or discontinue use if mitigations are unavailable.