Roundcube

Webmail

107 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Medienbericht
  • EPSS 0.28%
  • Veröffentlicht 17.08.2026 13:01:26
  • Zuletzt bearbeitet 08.09.2026 16:33:34

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the modoboa driver of the password plugin could leak a Modoboa API authentication token to a user-controlled host via crafted session data. This issue only affects Roundcube instances using t...

Medienbericht
  • EPSS 0.25%
  • Veröffentlicht 17.08.2026 12:58:48
  • Zuletzt bearbeitet 08.09.2026 16:49:25

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the LDAP search filter was subject to injection via unescaped %u/%fu/%d substitution, which may lead to information disclosure or privilege escalation.

Medienbericht
  • EPSS 0.34%
  • Veröffentlicht 17.08.2026 12:56:47
  • Zuletzt bearbeitet 08.09.2026 18:43:44

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. This issue e...

Medienbericht
  • EPSS 0.29%
  • Veröffentlicht 17.08.2026 12:53:50
  • Zuletzt bearbeitet 08.09.2026 18:46:33

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper rule name quoting could lead to managesieve_disabled_actions setting bypass via a crafted rule name in a Sieve script. This issue only affects Roundcube instances using the managesie...

Medienbericht
  • EPSS 0.31%
  • Veröffentlicht 17.08.2026 12:50:51
  • Zuletzt bearbeitet 10.09.2026 19:18:27

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed url() in a FuncIRI attribute of an SVG image could evade the remote image blocking, which may lead to information disclosure or privilege escalation.

Medienbericht
  • EPSS 1.32%
  • Veröffentlicht 17.08.2026 12:48:41
  • Zuletzt bearbeitet 08.09.2026 18:59:00

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, mail search and LITERAL+ byte-count desynchronization could lead to information disclosure or privilege escalation via IMAP command injection.

Medienbericht
  • EPSS 0.32%
  • Veröffentlicht 17.08.2026 12:45:56
  • Zuletzt bearbeitet 08.09.2026 19:18:05

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper HTML/CSS sanitization of the SVG animate "by" attribute may lead to remote image blocking bypass, which in turn may lead to information disclosure or privilege escalation.

Medienbericht
  • EPSS 0.22%
  • Veröffentlicht 17.08.2026 12:42:51
  • Zuletzt bearbeitet 08.09.2026 19:10:56

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the "Add to address book" action was subject to stored XSS.

Medienbericht
  • EPSS 0.27%
  • Veröffentlicht 17.08.2026 12:40:29
  • Zuletzt bearbeitet 08.09.2026 19:10:00

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, responses from the CSS (Cascading Style Sheets) proxy were not validated, which may result in information disclosure or XSS (cross-site scripting) via MIME sniffing.

Medienbericht
  • EPSS 0.77%
  • Veröffentlicht 17.08.2026 12:37:45
  • Zuletzt bearbeitet 08.09.2026 19:09:05

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the cmd_learn driver of the markasjunk plugin is subject to remote code execution via crafted placeholder replacement values. This issue only affects Roundcube instances using the markasjunk ...