Roundcube
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Roundcube product.
RSS Feeds for Roundcube security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Roundcube products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Roundcube Sorted by Most Security Vulnerabilities since 2018
Known Exploited Roundcube Vulnerabilities
The following Roundcube vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.
| Title | Description | Added |
|---|---|---|
| RoundCube Webmail Deserialization of Untrusted Data Vulnerability |
RoundCube Webmail contains a deserialization of untrusted data vulnerability that allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php. CVE-2025-49113 Exploit Probability: 97.7% |
February 20, 2026 |
| RoundCube Webmail Cross-site Scripting Vulnerability |
RoundCube Webmail contains a cross-site scripting vulnerability via the animate tag in an SVG document. CVE-2025-68461 Exploit Probability: 20.1% |
February 20, 2026 |
| RoundCube Webmail Cross-Site Scripting Vulnerability |
RoundCube Webmail contains a cross-site scripting vulnerability. This vulnerability could allow a remote attacker to steal and send emails of a victim via a crafted e-mail message that abuses a Desanitization issue in message_body() in program/actions/mail/show.php. CVE-2024-42009 Exploit Probability: 79.6% |
June 9, 2025 |
| RoundCube Webmail Cross-Site Scripting (XSS) Vulnerability |
RoundCube Webmail contains a cross-site scripting (XSS) vulnerability in the handling of SVG animate attributes that allows a remote attacker to run malicious JavaScript code. CVE-2024-37383 Exploit Probability: 73.3% |
October 24, 2024 |
| Roundcube Webmail Cross-Site Scripting (XSS) Vulnerability |
Roundcube Webmail contains a cross-site scripting (XSS) vulnerability that allows a remote attacker to manipulate data via a malicious XML attachment. CVE-2020-13965 Exploit Probability: 76.6% |
June 26, 2024 |
| Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability |
Roundcube Webmail contains a persistent cross-site scripting (XSS) vulnerability that can lead to information disclosure via malicious link references in plain/text messages. CVE-2023-43770 Exploit Probability: 58.5% |
February 12, 2024 |
| Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability |
Roundcube Webmail contains a persistent cross-site scripting (XSS) vulnerability that allows a remote attacker to run malicious JavaScript code. CVE-2023-5631 Exploit Probability: 75.9% |
October 26, 2023 |
| Roundcube Webmail Cross-Site Scripting (XSS) Vulnerability |
Roundcube Webmail contains a cross-site scripting (XSS) vulnerability that allows an attacker to send a plain text e-mail message with Javascript in a link reference element that is mishandled by linkref_addinindex in rcube_string_replacer.php. CVE-2020-35730 Exploit Probability: 32.7% |
June 22, 2023 |
| Roundcube Webmail Remote Code Execution Vulnerability |
Roundcube Webmail contains an remote code execution vulnerability that allows attackers to execute code via shell metacharacters in a configuration setting for im_convert_path or im_identify_path. CVE-2020-12641 Exploit Probability: 84.3% |
June 22, 2023 |
| Roundcube Webmail SQL Injection Vulnerability |
Roundcube Webmail is vulnerable to SQL injection via search or search_params. CVE-2021-44026 Exploit Probability: 41.9% |
June 22, 2023 |
| Roundcube Webmail File Disclosure Vulnerability |
Allows unauthorized access to arbitrary files on the host's filesystem, including configuration files. The issue is related to file-based attachment plugins and _task=settings&_action=upload-display&_from=timezone requests. CVE-2017-16651 Exploit Probability: 36.7% |
November 3, 2021 |
Of the known exploited vulnerabilities above, 7 are in the top 1%, or the 99th percentile of the EPSS exploit probability rankings. 4 known exploited Roundcube vulnerabilities are in the top 5% (95th percentile or greater) of the EPSS exploit probability rankings.
By the Year
In 2026 there have been 36 vulnerabilities in Roundcube with an average score of 5.7 out of ten. Last year, in 2025 Roundcube had 4 security vulnerabilities published. That is, 32 more vulnerabilities have already been reported in 2026 as compared to last year. Last year, the average CVE base score was greater by 2.39
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 36 | 5.71 |
| 2025 | 4 | 8.10 |
| 2024 | 5 | 8.23 |
| 2023 | 3 | 6.10 |
| 2022 | 1 | 6.10 |
| 2021 | 5 | 7.10 |
| 2020 | 9 | 6.88 |
| 2019 | 2 | 4.30 |
| 2018 | 5 | 7.48 |
It may take a day or so for new Roundcube vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Roundcube Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-75010 | Aug 17, 2026 |
Roundcube Webmail 1.7.3: Modoboa Password Plugin Token LeakIn Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the modoboa driver of the password plugin could leak a Modoboa API authentication token to a user-controlled host via crafted session data. This issue only affects Roundcube instances using the password plugin with its modoboa driver. |
|
| CVE-2026-75007 | Aug 17, 2026 |
LDAP Injection in Roundcube Webmail 1.6.18-1.7.2 (LDAP Filter)In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the LDAP search filter was subject to injection via unescaped %u/%fu/%d substitution, which may lead to information disclosure or privilege escalation. |
|
| CVE-2026-75006 | Aug 17, 2026 |
Roundcube 1.6/1.7 CSS Sanitization SSRF/Info DisclosureIn Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. This issue exists because of insufficient fixes for CVE-2026-35540, CVE-2026-48843 and CVE-2026-62643. |
|
| CVE-2026-75004 | Aug 17, 2026 |
Roundcube Webmail 1.6.18/1.7.x Rule Name Quoting Bypass via managesieve pluginIn Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper rule name quoting could lead to managesieve_disabled_actions setting bypass via a crafted rule name in a Sieve script. This issue only affects Roundcube instances using the managesieve plugin. |
|
| CVE-2026-75003 | Aug 17, 2026 |
Roundcube Webmail <1.6.18/1.7.x<1.7.3: SVG FuncIRI URL EvasionIn Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed url() in a FuncIRI attribute of an SVG image could evade the remote image blocking, which may lead to information disclosure or privilege escalation. |
|
| CVE-2026-75002 | Aug 17, 2026 |
Roundcube Webmail 1.6.18/1.7.3 IMAP Command Injection PrivEscIn Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, mail search and LITERAL+ byte-count desynchronization could lead to information disclosure or privilege escalation via IMAP command injection. |
|
| CVE-2026-75000 | Aug 17, 2026 |
Roundcube Webmail <=1.6.18/1.7.2 Improper SVG Sanitization, Block BypassIn Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper HTML/CSS sanitization of the SVG animate "by" attribute may lead to remote image blocking bypass, which in turn may lead to information disclosure or privilege escalation. |
|
| CVE-2026-74999 | Aug 17, 2026 |
Roundcube Webmail XSS via Add to addr book before 1.6.18/1.7.3In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the "Add to address book" action was subject to stored XSS. |
|
| CVE-2026-74998 | Aug 17, 2026 |
Roundcube <=1.6.18, <=1.7.2: Unvalidated CSS Proxy XSS/Info Disclosure via MIME SniffingIn Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, responses from the CSS (Cascading Style Sheets) proxy were not validated, which may result in information disclosure or XSS (cross-site scripting) via MIME sniffing. |
|
| CVE-2026-74997 | Aug 17, 2026 |
Roundcube RCE via cmd_learn Driver in markasjunk Plugin (pre1.6.18/1.7.3)In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the cmd_learn driver of the markasjunk plugin is subject to remote code execution via crafted placeholder replacement values. This issue only affects Roundcube instances using the markasjunk plugin with its cmd_learn driver. |
|