Roundcube Webmail
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Roundcube Webmail.
Known Exploited Roundcube Webmail Vulnerabilities
The following Roundcube Webmail vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.
| Title | Description | Added |
|---|---|---|
| RoundCube Webmail Deserialization of Untrusted Data Vulnerability |
RoundCube Webmail contains a deserialization of untrusted data vulnerability that allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php. CVE-2025-49113 Exploit Probability: 97.7% |
February 20, 2026 |
| RoundCube Webmail Cross-site Scripting Vulnerability |
RoundCube Webmail contains a cross-site scripting vulnerability via the animate tag in an SVG document. CVE-2025-68461 Exploit Probability: 20.1% |
February 20, 2026 |
| RoundCube Webmail Cross-Site Scripting Vulnerability |
RoundCube Webmail contains a cross-site scripting vulnerability. This vulnerability could allow a remote attacker to steal and send emails of a victim via a crafted e-mail message that abuses a Desanitization issue in message_body() in program/actions/mail/show.php. CVE-2024-42009 Exploit Probability: 79.6% |
June 9, 2025 |
| RoundCube Webmail Cross-Site Scripting (XSS) Vulnerability |
RoundCube Webmail contains a cross-site scripting (XSS) vulnerability in the handling of SVG animate attributes that allows a remote attacker to run malicious JavaScript code. CVE-2024-37383 Exploit Probability: 73.3% |
October 24, 2024 |
| Roundcube Webmail Cross-Site Scripting (XSS) Vulnerability |
Roundcube Webmail contains a cross-site scripting (XSS) vulnerability that allows a remote attacker to manipulate data via a malicious XML attachment. CVE-2020-13965 Exploit Probability: 76.6% |
June 26, 2024 |
| Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability |
Roundcube Webmail contains a persistent cross-site scripting (XSS) vulnerability that can lead to information disclosure via malicious link references in plain/text messages. CVE-2023-43770 Exploit Probability: 58.5% |
February 12, 2024 |
| Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability |
Roundcube Webmail contains a persistent cross-site scripting (XSS) vulnerability that allows a remote attacker to run malicious JavaScript code. CVE-2023-5631 Exploit Probability: 75.9% |
October 26, 2023 |
Of the known exploited vulnerabilities above, 6 are in the top 1%, or the 99th percentile of the EPSS exploit probability rankings. The vulnerability CVE-2025-68461: RoundCube Webmail Cross-site Scripting Vulnerability is in the top 5% of the currently known exploitable vulnerabilities.
By the Year
In 2026 there have been 36 vulnerabilities in Roundcube Webmail with an average score of 5.7 out of ten. Last year, in 2025 Webmail had 4 security vulnerabilities published. That is, 32 more vulnerabilities have already been reported in 2026 as compared to last year. Last year, the average CVE base score was greater by 2.39
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 36 | 5.71 |
| 2025 | 4 | 8.10 |
| 2024 | 5 | 8.23 |
| 2023 | 3 | 6.10 |
| 2022 | 0 | 0.00 |
| 2021 | 5 | 7.10 |
| 2020 | 9 | 6.88 |
| 2019 | 2 | 4.30 |
| 2018 | 5 | 7.48 |
It may take a day or so for new Webmail vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Roundcube Webmail Security Vulnerabilities
Roundcube Webmail 1.7.3: Modoboa Password Plugin Token Leak
CVE-2026-75010
6.4 - Medium
- August 17, 2026
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the modoboa driver of the password plugin could leak a Modoboa API authentication token to a user-controlled host via crafted session data. This issue only affects Roundcube instances using the password plugin with its modoboa driver.
Incorrect Resource Transfer Between Spheres
LDAP Injection in Roundcube Webmail 1.6.18-1.7.2 (LDAP Filter)
CVE-2026-75007
5.4 - Medium
- August 17, 2026
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the LDAP search filter was subject to injection via unescaped %u/%fu/%d substitution, which may lead to information disclosure or privilege escalation.
Command Injection
Roundcube 1.6/1.7 CSS Sanitization SSRF/Info Disclosure
CVE-2026-75006
5.8 - Medium
- August 17, 2026
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. This issue exists because of insufficient fixes for CVE-2026-35540, CVE-2026-48843 and CVE-2026-62643.
SSRF
Roundcube Webmail 1.6.18/1.7.x Rule Name Quoting Bypass via managesieve plugin
CVE-2026-75004
4.3 - Medium
- August 17, 2026
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper rule name quoting could lead to managesieve_disabled_actions setting bypass via a crafted rule name in a Sieve script. This issue only affects Roundcube instances using the managesieve plugin.
Command Injection
Roundcube Webmail <1.6.18/1.7.x<1.7.3: SVG FuncIRI URL Evasion
CVE-2026-75003
5.8 - Medium
- August 17, 2026
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed url() in a FuncIRI attribute of an SVG image could evade the remote image blocking, which may lead to information disclosure or privilege escalation.
Incorrect Resource Transfer Between Spheres
Roundcube Webmail 1.6.18/1.7.3 IMAP Command Injection PrivEsc
CVE-2026-75002
7.1 - High
- August 17, 2026
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, mail search and LITERAL+ byte-count desynchronization could lead to information disclosure or privilege escalation via IMAP command injection.
Command Injection
Roundcube Webmail <=1.6.18/1.7.2 Improper SVG Sanitization, Block Bypass
CVE-2026-75000
5.8 - Medium
- August 17, 2026
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper HTML/CSS sanitization of the SVG animate "by" attribute may lead to remote image blocking bypass, which in turn may lead to information disclosure or privilege escalation.
Incorrect Resource Transfer Between Spheres
Roundcube Webmail XSS via Add to addr book before 1.6.18/1.7.3
CVE-2026-74999
5.4 - Medium
- August 17, 2026
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the "Add to address book" action was subject to stored XSS.
XSS
Roundcube <=1.6.18, <=1.7.2: Unvalidated CSS Proxy XSS/Info Disclosure via MIME Sniffing
CVE-2026-74998
7.2 - High
- August 17, 2026
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, responses from the CSS (Cascading Style Sheets) proxy were not validated, which may result in information disclosure or XSS (cross-site scripting) via MIME sniffing.
XSS
Roundcube RCE via cmd_learn Driver in markasjunk Plugin (pre1.6.18/1.7.3)
CVE-2026-74997
8.8 - High
- August 17, 2026
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the cmd_learn driver of the markasjunk plugin is subject to remote code execution via crafted placeholder replacement values. This issue only affects Roundcube instances using the markasjunk plugin with its cmd_learn driver.
Shell injection
Roundcube Webmail <=1.6.17, <=1.7.1 Stored XSS via MIME
CVE-2026-54432
4.7 - Medium
- July 14, 2026
Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2 allows Stored Cross-Site Scripting (XSS). The issue occurs because the attachment MIME type is not properly escaped on the attachment-validation warning page.
XSS
Roundcube Webmail 1.x Stored XSS via crafted email before 1.6.17/1.7.2
CVE-2026-54433
7.2 - High
- July 14, 2026
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafted plain-text email message. The attacker-controlled JavaScript executes within the victim's authenticated session simply by opening or previewing the message (zero-click).
XSS
Roundcube Webmail <1.6.17/1.7.2 Password Plugin Username Spoofing Account Takeover
CVE-2026-62644
6.4 - Medium
- July 14, 2026
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing via session data, which could lead to account takeover.
Authentication Bypass by Spoofing
Roundcube Webmail <=1.6.17/<=1.7.1: CSS Sanitization Flaw Enables SSRF
CVE-2026-62643
7.2 - High
- July 14, 2026
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. NOTE: this issue exists because of insufficient fixes for CVE-2026-35540 and CVE-2026-48843.
SSRF
Roundcube Webmail TNEF Decoder Infinite Loop DoS before 1.6.17/1.7.2
CVE-2026-62642
4.3 - Medium
- July 14, 2026
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, an infinite loop was discovered in the TNEF decoder, which may lead to denial of service upon opening an email with a TNEF attachment.
Infinite Loop
Roundcube Webmail TNEF Decoder DOS via Compressed-RTF before 1.7.2
CVE-2026-62641
4.3 - Medium
- July 14, 2026
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the TNEF decoder was subject to denial of service via a crafted compressed-RTF size.
Allocation of Resources Without Limits or Throttling
Roundcube HTML Sanitization Allows Loopback URLs
CVE-2026-9818
- May 28, 2026
Roundcube Webmail 1.6.x <1.6.16 & 1.7.x <1.7.1 XSS via Unsanitized Subject
CVE-2026-48849
4.4 - Medium
- May 25, 2026
In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, an unsanitized subject field in the draft restored value could lead to stored XSS/HTML/CSS injection on shared mailboxes.
XSS
Roundcube <=1.7 HTML Sanitization Flaw: CSS Injection via SVG animate(attributeName)
CVE-2026-48848
7.2 - High
- May 25, 2026
Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7 has insufficient HTML sanitization that could lead to Cascading Style Sheets (CSS) injection via an SVG document that has an animate element with the attributeName attribute.
XSS
Roundcube Webmail 1.6.x<1.6.16/1.7.x<1.7.1 Pre-Auth Arbitrary File Deletion via Redis/Memcache
CVE-2026-48847
3.7 - Low
- May 25, 2026
Roundcube Webmail 1.6.x before 1.6.16, and 1.7.x before 1.7.1 allows pre-authentication arbitrary file deletion via redis/memcache session poisoning bypass.
Incorrect Resource Transfer Between Spheres
CVE-2026-48846 Roundcube: Remote Image Blocking Bypass via CSS var()
CVE-2026-48846
6.5 - Medium
- May 25, 2026
In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, the remote image blocking feature can be bypassed via a crafted CSS var() value in an e-mail message, which may lead to information disclosure or access-control bypass.
Incorrect Resource Transfer Between Spheres
Remote Img Block Bypass: Roundcube 1.6.14-1.6.16 & 1.7.x<1.7.1
CVE-2026-48845
6.5 - Medium
- May 25, 2026
In Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16 and 1.7.x before 1.7.1, remote image blocking was not honored for URLs pointing to local/private destinations, which may lead to information disclosure or privilege escalation via a text/html email message.
Incorrect Resource Transfer Between Spheres
Roundcube Webmail LDAP Autovalues Code Injection Before v1.6.16 & v1.7.1
CVE-2026-48844
7.5 - High
- May 25, 2026
Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has insecure code evaluation logic in LDAP the autovalues option that could lead to code injection. (Support for code evaluation has been removed in 1.6.16 and 1.7.1.)
Always-Incorrect Control Flow Implementation
Roundcube Webmail 1.6.x 1.6.141.6.16 & 1.7.x<1.7.1: CSS SSRF/InfoLeak
CVE-2026-48843
7.2 - High
- May 25, 2026
Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16,and 1.7.x before 1.7.1 has Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. The issue stems from an insufficient fix for CVE-2026-35540.
SSRF
Pre-Authentication SQL Injection in Roundcube virtuser_query Plugin (1.6.x<1.6.16, 1.7.x<1.7.1)
CVE-2026-48842
8.1 - High
- May 25, 2026
Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via a preg_replace() backslash escape bypass.
SQL Injection
Roundcube Webmail SVG img block bypass <1.5.15/1.6.15
CVE-2026-35545
5.3 - Medium
- April 03, 2026
An issue was discovered in Roundcube Webmail before 1.5.15 and 1.6.15. The remote image blocking feature can be bypassed via SVG content in an e-mail message. This may lead to information disclosure or access-control bypass. This involves the animate element with attributeName=fill/filter/stroke.
Incorrect Resource Transfer Between Spheres
Roundcube Webmail <1.5.14/1.6.14 CSS Sanitization Bypass via !important
CVE-2026-35544
5.3 - Medium
- April 03, 2026
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to a fixed-position mitigation bypass via the use of !important.
Incorrect Resource Transfer Between Spheres
Roundcube Webmail <1.5.14/1.6.14: SVG Image Blocking Bypass via animate attrs
CVE-2026-35543
5.3 - Medium
- April 03, 2026
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via SVG content (with animate attributes) in an e-mail message. This may lead to information disclosure or access-control bypass.
Incorrect Resource Transfer Between Spheres
Roundcube 1.6.13 Remote Image Block Bypass via BODY background
CVE-2026-35542
5.3 - Medium
- April 03, 2026
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via a crafted background attribute of a BODY element in an e-mail message. This may lead to information disclosure or access-control bypass.
Incorrect Resource Transfer Between Spheres
Roundcube <1.6.14 Password Plugin Type Confusion Enables Password Change
CVE-2026-35541
4.2 - Medium
- April 03, 2026
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Incorrect password comparison in the password plugin could lead to type confusion that allows a password change without knowing the old password.
Object Type Confusion
Roundcube 1.6.0bef.1.6.14: CSS SSRF/Info Disclosure
CVE-2026-35540
5.4 - Medium
- April 03, 2026
An issue was discovered in Roundcube Webmail 1.6.0 before 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts.
Incorrect Resource Transfer Between Spheres
XSS in Roundcube <1.5.14/1.6.14 via HTML attachment preview
CVE-2026-35539
6.1 - Medium
- April 03, 2026
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. XSS exists because of insufficient HTML attachment sanitization in preview mode. A victim must preview a text/html attachment.
XSS
Roundcube Webmail <1.5.14/1.6.14: IMAP Injection & CSRF via UNSCANNED SEARCH
CVE-2026-35538
3.1 - Low
- April 03, 2026
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsanitized IMAP SEARCH command arguments could lead to IMAP injection or CSRF bypass during mail search.
Argument Injection
Roundcube <1.5.14/1.6.14 unsafe deserialization: arb file write via session
CVE-2026-35537
3.7 - Low
- April 03, 2026
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsafe deserialization in the redis/memcache session handler may lead to arbitrary file write operations by unauthenticated attackers via crafted session data.
Marshaling, Unmarshaling
Roundcube Webmail CSS Injection v1.5.13/1.6.13 (CVE-2026-26079)
CVE-2026-26079
4.7 - Medium
- February 11, 2026
Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13 allows Cascading Style Sheets (CSS) injection, e.g., because comments are mishandled.
Inclusion of Functionality from Untrusted Control Sphere
Roundcube <1.5.13/1.6.13 fails to block SVG feImage when Block remote images enabled
CVE-2026-25916
4.3 - Medium
- February 09, 2026
Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13, when "Block remote images" is used, does not block SVG feImage.
Unprotected Alternate Channel
CVE-2025-68461 XSS via SVG animate tag in Roundcube Webmail <1.5.12 / <1.6.12
CVE-2025-68461
7.2 - High
- December 18, 2025
Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document.
XSS
Roundcube Webmail 1.5.12 & 1.6.12 info disclosure via HTML style sanitizer
CVE-2025-68460
7.2 - High
- December 18, 2025
Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a information disclosure vulnerability in the HTML style sanitizer.
Output Sanitization
RCE in Roundcube <1.6.11 via Unvalidated _from Param (PHP OD)
CVE-2025-49113
9.9 - Critical
- June 02, 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP Object Deserialization.
Marshaling, Unmarshaling
XSS via Attachment Upload in Roundcube Webmail 1.6.9
CVE-2024-57004
- February 03, 2025
Cross-Site Scripting (XSS) vulnerability in Roundcube Webmail 1.6.9 allows remote authenticated users to upload a malicious file as an email attachment, leading to the triggering of the XSS by visiting the SENT session.
XSS in Roundcube 1.5.7/1.6.7 rcmail_action_mail_get
CVE-2024-42008
9.3 - Critical
- August 05, 2024
A Cross-Site Scripting vulnerability in rcmail_action_mail_get->run() in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a malicious e-mail attachment served with a dangerous Content-Type header.
XSS
XSS via message_body desanitization in Roundcube <=1.6.7 (CVE-2024-42009)
CVE-2024-42009
9.3 - Critical
- August 05, 2024
A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a crafted e-mail message that abuses a Desanitization issue in message_body() in program/actions/mail/show.php.
XSS
Roundcube <=1.5.7 & 1.6.x <=1.6.7 CmdInject via im_convert/im_identify
CVE-2024-37385
- June 07, 2024
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 on Windows allows command injection via im_convert_path and im_identify_path. NOTE: this issue exists because of an incomplete fix for CVE-2020-12641.
Roundcube Webmail XSS via SVG animate (<=1.5.6/1.6.6)
CVE-2024-37383
6.1 - Medium
- June 07, 2024
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.
XSS
Roundcube Webmail <=1.5.7/1.6.x<1.6.7 XSS via user preference list columns
CVE-2024-37384
- June 07, 2024
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via list columns from user preferences.
Roundcube XSS via Header before 1.5.6/1.6.5 (Content-Type/Disposition)
CVE-2023-47272
6.1 - Medium
- November 06, 2023
Roundcube 1.5.x before 1.5.6 and 1.6.x before 1.6.5 allows XSS via a Content-Type or Content-Disposition header (used for attachment preview or download).
XSS
Roundcube <=1.4.15/1.5.x<1.5.5/1.6.x<1.6.4 Stored XSS via SVG in HTML mail
CVE-2023-5631
6.1 - Medium
- October 18, 2023
Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a crafted SVG document because of program/lib/Roundcube/rcube_washtml.php behavior. This could allow a remote attacker to load arbitrary JavaScript code.
XSS
Roundcube<1.4.14,1.5.x<1.5.4,1.6.x<1.6.3 XSS via plain email links (rcube_string_replacer.php)
CVE-2023-43770
6.1 - Medium
- September 22, 2023
Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of program/lib/Roundcube/rcube_string_replacer.php behavior.
XSS
Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection
CVE-2021-44026
9.8 - Critical
- November 19, 2021
Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.
SQL Injection
Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to XSS in handling an attachment's filename extension when displaying a MIME type warning message.
CVE-2021-44025
6.1 - Medium
- November 19, 2021
Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to XSS in handling an attachment's filename extension when displaying a MIME type warning message.
XSS
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Roundcube Webmail or by Roundcube? Click the Watch button to subscribe.