CVE-2025-49113
- EPSS 85.24%
- Published 02.06.2025 00:00:00
- Last modified 12.06.2025 17:15:29
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP Object Deserialization.
CVE-2024-42009
- EPSS 88.58%
- Published 05.08.2024 19:15:38
- Last modified 11.06.2025 15:46:19
A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a crafted e-mail message that abuses a Desanitization issue in message_body() in program/actions...
CVE-2024-42008
- EPSS 54.68%
- Published 05.08.2024 19:15:38
- Last modified 13.03.2025 16:15:21
A Cross-Site Scripting vulnerability in rcmail_action_mail_get->run() in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a malicious e-mail attachment served with a dangerous Content-T...
CVE-2024-37385
- EPSS 0.8%
- Published 07.06.2024 04:15:30
- Last modified 01.05.2025 19:49:21
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 on Windows allows command injection via im_convert_path and im_identify_path. NOTE: this issue exists because of an incomplete fix for CVE-2020-12641.
CVE-2024-37384
- EPSS 0.22%
- Published 07.06.2024 04:15:30
- Last modified 01.05.2025 19:51:01
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via list columns from user preferences.
CVE-2024-37383
- EPSS 61.42%
- Published 07.06.2024 04:15:30
- Last modified 20.12.2024 16:52:05
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.
CVE-2023-47272
- EPSS 0.65%
- Published 06.11.2023 00:15:09
- Last modified 21.11.2024 08:30:05
Roundcube 1.5.x before 1.5.6 and 1.6.x before 1.6.5 allows XSS via a Content-Type or Content-Disposition header (used for attachment preview or download).
CVE-2023-5631
- EPSS 91.01%
- Published 18.10.2023 15:15:08
- Last modified 19.03.2025 20:57:50
Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a crafted SVG document because of program/lib/Roundcube/rcube_washtml.php behavior. This could allow a remote attacker to load arbi...
CVE-2023-43770
- EPSS 75.03%
- Published 22.09.2023 06:15:10
- Last modified 20.12.2024 17:40:26
Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of program/lib/Roundcube/rcube_string_replacer.php behavior.
CVE-2021-44026
- EPSS 66.14%
- Published 19.11.2021 04:15:07
- Last modified 14.03.2025 16:47:31
Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.