CVE-2025-68461
- EPSS 0.01%
- Veröffentlicht 18.12.2025 05:00:54
- Zuletzt bearbeitet 02.01.2026 16:21:51
Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document.
CVE-2025-68460
- EPSS 0.05%
- Veröffentlicht 18.12.2025 04:54:13
- Zuletzt bearbeitet 02.01.2026 16:25:43
Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a information disclosure vulnerability in the HTML style sanitizer.
CVE-2025-49113
- EPSS 91.84%
- Veröffentlicht 02.06.2025 00:00:00
- Zuletzt bearbeitet 22.12.2025 18:00:36
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP Object Deserialization.
CVE-2024-57004
- EPSS 0.15%
- Veröffentlicht 03.02.2025 19:15:12
- Zuletzt bearbeitet 22.12.2025 16:03:05
Cross-Site Scripting (XSS) vulnerability in Roundcube Webmail 1.6.9 allows remote authenticated users to upload a malicious file as an email attachment, leading to the triggering of the XSS by visiting the SENT session.
CVE-2024-42009
- EPSS 91.22%
- Veröffentlicht 05.08.2024 19:15:38
- Zuletzt bearbeitet 04.11.2025 15:01:04
A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a crafted e-mail message that abuses a Desanitization issue in message_body() in program/actions...
CVE-2024-42008
- EPSS 58.57%
- Veröffentlicht 05.08.2024 19:15:38
- Zuletzt bearbeitet 13.03.2025 16:15:21
A Cross-Site Scripting vulnerability in rcmail_action_mail_get->run() in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a malicious e-mail attachment served with a dangerous Content-T...
CVE-2024-37383
- EPSS 66.36%
- Veröffentlicht 07.06.2024 04:15:30
- Zuletzt bearbeitet 31.10.2025 12:48:27
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.
CVE-2024-37384
- EPSS 0.33%
- Veröffentlicht 07.06.2024 04:15:30
- Zuletzt bearbeitet 01.05.2025 19:51:01
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via list columns from user preferences.
CVE-2024-37385
- EPSS 1.09%
- Veröffentlicht 07.06.2024 04:15:30
- Zuletzt bearbeitet 01.05.2025 19:49:21
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 on Windows allows command injection via im_convert_path and im_identify_path. NOTE: this issue exists because of an incomplete fix for CVE-2020-12641.
CVE-2023-47272
- EPSS 0.65%
- Veröffentlicht 06.11.2023 00:15:09
- Zuletzt bearbeitet 21.11.2024 08:30:05
Roundcube 1.5.x before 1.5.6 and 1.6.x before 1.6.5 allows XSS via a Content-Type or Content-Disposition header (used for attachment preview or download).