CVE-2026-54432
- EPSS 0.22%
- Veröffentlicht 14.07.2026 16:21:55
- Zuletzt bearbeitet 15.07.2026 20:08:02
Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2 allows Stored Cross-Site Scripting (XSS). The issue occurs because the attachment MIME type is not properly escaped on the attachment-validation warning page.
- EPSS 0.31%
- Veröffentlicht 14.07.2026 16:18:16
- Zuletzt bearbeitet 17.07.2026 19:24:24
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafted plain-text email message. The attacker-controlled JavaScript executes within the victim's authenticated session simply by opening or p...
CVE-2026-62641
- EPSS 0.25%
- Veröffentlicht 14.07.2026 16:17:04
- Zuletzt bearbeitet 20.07.2026 12:56:55
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the TNEF decoder was subject to denial of service via a crafted compressed-RTF size.
CVE-2026-62642
- EPSS 0.28%
- Veröffentlicht 14.07.2026 16:17:04
- Zuletzt bearbeitet 20.07.2026 12:55:28
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, an infinite loop was discovered in the TNEF decoder, which may lead to denial of service upon opening an email with a TNEF attachment.
- EPSS 0.25%
- Veröffentlicht 14.07.2026 16:17:04
- Zuletzt bearbeitet 20.07.2026 12:50:11
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. NOTE: this i...
CVE-2026-62644
- EPSS 0.26%
- Veröffentlicht 14.07.2026 16:17:04
- Zuletzt bearbeitet 20.07.2026 12:41:22
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing via session data, which could lead to account takeover.
CVE-2026-9818
- EPSS -
- Veröffentlicht 28.05.2026 12:16:05
- Zuletzt bearbeitet 28.05.2026 17:16:36
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-48849
- EPSS 0.24%
- Veröffentlicht 25.05.2026 19:30:38
- Zuletzt bearbeitet 24.07.2026 10:10:00
In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, an unsanitized subject field in the draft restored value could lead to stored XSS/HTML/CSS injection on shared mailboxes.
CVE-2026-48848
- EPSS 0.39%
- Veröffentlicht 25.05.2026 19:27:54
- Zuletzt bearbeitet 24.07.2026 10:10:00
Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7 has insufficient HTML sanitization that could lead to Cascading Style Sheets (CSS) injection via an SVG document that has an animate element with the attributeName attribute.
CVE-2026-48847
- EPSS 0.43%
- Veröffentlicht 25.05.2026 19:23:40
- Zuletzt bearbeitet 24.07.2026 10:10:00
Roundcube Webmail 1.6.x before 1.6.16, and 1.7.x before 1.7.1 allows pre-authentication arbitrary file deletion via redis/memcache session poisoning bypass.