Roundcube

Webmail

107 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.31%
  • Veröffentlicht 03.04.2026 03:47:51
  • Zuletzt bearbeitet 24.07.2026 21:10:00

An issue was discovered in Roundcube Webmail 1.6.0 before 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts.

  • EPSS 0.25%
  • Veröffentlicht 03.04.2026 03:39:17
  • Zuletzt bearbeitet 24.07.2026 21:10:00

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. XSS exists because of insufficient HTML attachment sanitization in preview mode. A victim must preview a text/html attachment.

  • EPSS 0.28%
  • Veröffentlicht 03.04.2026 03:35:36
  • Zuletzt bearbeitet 24.07.2026 21:10:00

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsanitized IMAP SEARCH command arguments could lead to IMAP injection or CSRF bypass during mail search.

  • EPSS 0.48%
  • Veröffentlicht 03.04.2026 03:28:29
  • Zuletzt bearbeitet 24.07.2026 21:10:00

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsafe deserialization in the redis/memcache session handler may lead to arbitrary file write operations by unauthenticated attackers via crafted session data.

  • EPSS 0.29%
  • Veröffentlicht 11.02.2026 04:27:24
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13 allows Cascading Style Sheets (CSS) injection, e.g., because comments are mishandled.

  • EPSS 0.63%
  • Veröffentlicht 09.02.2026 08:14:10
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13, when "Block remote images" is used, does not block SVG feImage.

Warnung Medienbericht
  • EPSS 20.78%
  • Veröffentlicht 18.12.2025 05:00:54
  • Zuletzt bearbeitet 23.02.2026 13:24:12

Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document.

  • EPSS 0.28%
  • Veröffentlicht 18.12.2025 04:54:13
  • Zuletzt bearbeitet 02.01.2026 16:25:43

Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a information disclosure vulnerability in the HTML style sanitizer.

Warnung Medienbericht Exploit
  • EPSS 97.69%
  • Veröffentlicht 02.06.2025 00:00:00
  • Zuletzt bearbeitet 23.02.2026 13:24:21

Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP Object Deserialization.

Exploit
  • EPSS 28.82%
  • Veröffentlicht 03.02.2025 19:15:12
  • Zuletzt bearbeitet 22.12.2025 16:03:05

Cross-Site Scripting (XSS) vulnerability in Roundcube Webmail 1.6.9 allows remote authenticated users to upload a malicious file as an email attachment, leading to the triggering of the XSS by visiting the SENT session.