CVE-2026-35540
- EPSS 0.31%
- Veröffentlicht 03.04.2026 03:47:51
- Zuletzt bearbeitet 24.07.2026 21:10:00
An issue was discovered in Roundcube Webmail 1.6.0 before 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts.
CVE-2026-35539
- EPSS 0.25%
- Veröffentlicht 03.04.2026 03:39:17
- Zuletzt bearbeitet 24.07.2026 21:10:00
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. XSS exists because of insufficient HTML attachment sanitization in preview mode. A victim must preview a text/html attachment.
CVE-2026-35538
- EPSS 0.28%
- Veröffentlicht 03.04.2026 03:35:36
- Zuletzt bearbeitet 24.07.2026 21:10:00
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsanitized IMAP SEARCH command arguments could lead to IMAP injection or CSRF bypass during mail search.
CVE-2026-35537
- EPSS 0.48%
- Veröffentlicht 03.04.2026 03:28:29
- Zuletzt bearbeitet 24.07.2026 21:10:00
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsafe deserialization in the redis/memcache session handler may lead to arbitrary file write operations by unauthenticated attackers via crafted session data.
CVE-2026-26079
- EPSS 0.29%
- Veröffentlicht 11.02.2026 04:27:24
- Zuletzt bearbeitet 15.04.2026 00:35:42
Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13 allows Cascading Style Sheets (CSS) injection, e.g., because comments are mishandled.
CVE-2026-25916
- EPSS 0.63%
- Veröffentlicht 09.02.2026 08:14:10
- Zuletzt bearbeitet 15.04.2026 00:35:42
Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13, when "Block remote images" is used, does not block SVG feImage.
CVE-2025-68461
- EPSS 20.78%
- Veröffentlicht 18.12.2025 05:00:54
- Zuletzt bearbeitet 23.02.2026 13:24:12
Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document.
CVE-2025-68460
- EPSS 0.28%
- Veröffentlicht 18.12.2025 04:54:13
- Zuletzt bearbeitet 02.01.2026 16:25:43
Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a information disclosure vulnerability in the HTML style sanitizer.
CVE-2025-49113
- EPSS 97.69%
- Veröffentlicht 02.06.2025 00:00:00
- Zuletzt bearbeitet 23.02.2026 13:24:21
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP Object Deserialization.
CVE-2024-57004
- EPSS 28.82%
- Veröffentlicht 03.02.2025 19:15:12
- Zuletzt bearbeitet 22.12.2025 16:03:05
Cross-Site Scripting (XSS) vulnerability in Roundcube Webmail 1.6.9 allows remote authenticated users to upload a malicious file as an email attachment, leading to the triggering of the XSS by visiting the SENT session.