Roundcube

Webmail

107 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.41%
  • Veröffentlicht 25.05.2026 19:21:09
  • Zuletzt bearbeitet 24.07.2026 10:10:00

In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, the remote image blocking feature can be bypassed via a crafted CSS var() value in an e-mail message, which may lead to information disclosure or access-control bypass.

  • EPSS 0.38%
  • Veröffentlicht 25.05.2026 19:18:09
  • Zuletzt bearbeitet 24.07.2026 10:10:00

In Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16 and 1.7.x before 1.7.1, remote image blocking was not honored for URLs pointing to local/private destinations, which may lead to information disclosure or privilege escalation via a text/html email...

Medienbericht
  • EPSS 0.41%
  • Veröffentlicht 25.05.2026 19:14:48
  • Zuletzt bearbeitet 24.07.2026 10:10:00

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has insecure code evaluation logic in LDAP the autovalues option that could lead to code injection. (Support for code evaluation has been removed in 1.6.16 and 1.7.1.)

Medienbericht
  • EPSS 0.27%
  • Veröffentlicht 25.05.2026 19:11:04
  • Zuletzt bearbeitet 24.07.2026 10:10:00

Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16,and 1.7.x before 1.7.1 has Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network h...

Medienbericht
  • EPSS 0.76%
  • Veröffentlicht 25.05.2026 19:06:37
  • Zuletzt bearbeitet 25.09.2026 04:17:35

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via a preg_replace() backslash escape bypass.

  • EPSS 0.33%
  • Veröffentlicht 03.04.2026 04:02:06
  • Zuletzt bearbeitet 24.07.2026 21:10:00

An issue was discovered in Roundcube Webmail before 1.5.15 and 1.6.15. The remote image blocking feature can be bypassed via SVG content in an e-mail message. This may lead to information disclosure or access-control bypass. This involves the animate...

  • EPSS 0.37%
  • Veröffentlicht 03.04.2026 03:59:49
  • Zuletzt bearbeitet 24.07.2026 21:10:00

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to a fixed-position mitigation bypass via the use of !important.

  • EPSS 0.4%
  • Veröffentlicht 03.04.2026 03:57:06
  • Zuletzt bearbeitet 24.07.2026 21:10:00

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via SVG content (with animate attributes) in an e-mail message. This may lead to information disclosure or access-control bypass.

  • EPSS 0.4%
  • Veröffentlicht 03.04.2026 03:54:18
  • Zuletzt bearbeitet 24.07.2026 21:10:00

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via a crafted background attribute of a BODY element in an e-mail message. This may lead to information disclosure or access-cont...

  • EPSS 0.24%
  • Veröffentlicht 03.04.2026 03:50:47
  • Zuletzt bearbeitet 24.07.2026 21:10:00

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Incorrect password comparison in the password plugin could lead to type confusion that allows a password change without knowing the old password.