MidnightBSD

Advisories for roundcube

CVE-2005-4368 MEDIUM

roundcube webmail Alpha, with a default high verbose level ($rcmail_config['debug_level'] = 1), allows remote attackers to obtain the full path of the application via an invalid_task parameter, which leaks the path in an error message.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
roundcube webmail -
CVE-2010-0464 MEDIUM

Roundcube 0.3.1 and earlier does not request that the web browser avoid DNS prefetching of domain names contained in e-mail messages, which makes it easier for remote attackers to determine the network location of the webmail user by logging DNS requests.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
roundcube webmail 0.1.1
roundcube webmail 0.3
roundcube webmail *
roundcube webmail 0.2.1
roundcube webmail 0.2.2
roundcube webmail 0.1
roundcube webmail 0.2
CVE-2011-1491 LOW

The login form in Roundcube Webmail before 0.5.1 does not properly handle a correctly authenticated but unintended login attempt, which makes it easier for remote authenticated users to obtain sensitive information by arranging for a victim to login to the attacker's account and then compose an e-mail message, related to a "login CSRF" issue.

CVSS 2.0

Severity: LOW

Problem Type: CWE-20,

Products Affected

Vendor Product Version
roundcube webmail 0.4.1
roundcube webmail 0.3.1
roundcube webmail 0.1.1
roundcube webmail 0.4
roundcube webmail 0.3
roundcube webmail 0.4.2
roundcube webmail *
roundcube webmail 0.2.1
roundcube webmail 0.1
roundcube webmail 0.2
roundcube webmail 0.5
CVE-2011-1492 MEDIUM

steps/utils/modcss.inc in Roundcube Webmail before 0.5.1 does not properly verify that a request is an expected request for an external Cascading Style Sheets (CSS) stylesheet, which allows remote authenticated users to trigger arbitrary outbound TCP connections from the server, and possibly obtain sensitive information, via a crafted request.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
roundcube webmail 0.4.1
roundcube webmail 0.3.1
roundcube webmail 0.1.1
roundcube webmail 0.4
roundcube webmail 0.3
roundcube webmail 0.4.2
roundcube webmail *
roundcube webmail 0.2.1
roundcube webmail 0.1
roundcube webmail 0.2
roundcube webmail 0.5
CVE-2011-2937 MEDIUM

Cross-site scripting (XSS) vulnerability in the UI messages functionality in Roundcube Webmail before 0.5.4 allows remote attackers to inject arbitrary web script or HTML via the _mbox parameter to the default URI.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
roundcube webmail 0.4.1
roundcube webmail 0.3.1
roundcube webmail 0.3
roundcube webmail 0.5.1
roundcube webmail *
roundcube webmail 0.2.1
roundcube webmail 0.1
roundcube webmail 0.5
roundcube webmail 0.1.1
roundcube webmail 0.4
roundcube webmail 0.4.2
roundcube webmail 0.5.2
roundcube webmail 0.2
CVE-2011-4078 MEDIUM

include/iniset.php in Roundcube Webmail 0.5.4 and earlier, when PHP 5.3.7 or 5.3.8 is used, allows remote attackers to trigger a GET request for an arbitrary URL, and cause a denial of service (resource consumption and inbox outage), via a Subject header containing only a URL, a related issue to CVE-2011-3379.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
roundcube webmail 0.4.1
roundcube webmail 0.3.1
roundcube webmail 0.3
roundcube webmail 0.5.1
roundcube webmail *
roundcube webmail 0.2.1
roundcube webmail 0.1
roundcube webmail 0.5
roundcube webmail 0.1.1
roundcube webmail 0.4
roundcube webmail 0.4.2
roundcube webmail 0.5.2
roundcube webmail 0.5.3
roundcube webmail 0.2
CVE-2012-1253 LOW

Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 0.7, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via vectors involving an embedded image attachment.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
roundcube webmail 0.4.1
roundcube webmail 0.3.1
roundcube webmail 0.3
roundcube webmail 0.5.1
roundcube webmail *
roundcube webmail 0.2.1
roundcube webmail 0.1
roundcube webmail 0.5.4
roundcube webmail 0.5
roundcube webmail 0.1.1
roundcube webmail 0.4
roundcube webmail 0.4.2
roundcube webmail 0.5.2
roundcube webmail 0.5.3
roundcube webmail 0.2.2
roundcube webmail 0.2
CVE-2012-6121 MEDIUM

Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 0.8.5 allows remote attackers to inject arbitrary web script or HTML via a (1) data:text or (2) vbscript link.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
roundcube webmail 0.6
roundcube webmail 0.3.1
roundcube webmail 0.3
roundcube webmail 0.8.1
roundcube webmail 0.2.1
roundcube webmail 0.1
roundcube webmail 0.1.1
roundcube webmail 0.5.3
roundcube webmail 0.2.2
roundcube webmail 0.2
roundcube webmail 0.4.1
roundcube webmail 0.5.1
roundcube webmail *
roundcube webmail 0.5.4
roundcube webmail 0.7.2
roundcube webmail 0.5
roundcube webmail 0.7
roundcube webmail 0.4
roundcube webmail 0.8.0
roundcube webmail 0.4.2
roundcube webmail 0.8.3
roundcube webmail 0.5.2
roundcube webmail 0.7.1
roundcube webmail 0.7.3
roundcube webmail 0.8.2
CVE-2013-1904 MEDIUM

Absolute path traversal vulnerability in steps/mail/sendmail.inc in Roundcube Webmail before 0.7.3 and 0.8.x before 0.8.6 allows remote attackers to read arbitrary files via a full pathname in the _value parameter for the generic_message_footer setting in a save-perf action to index.php, as exploited in the wild in March 2013.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-22,

Products Affected

Vendor Product Version
roundcube webmail 0.6
roundcube webmail 0.3.1
roundcube webmail 0.3
roundcube webmail 0.8.1
roundcube webmail 0.2.1
roundcube webmail 0.1
roundcube webmail 0.8.4
roundcube webmail 0.1.1
roundcube webmail 0.5.3
roundcube webmail 0.2.2
roundcube webmail 0.2
roundcube webmail 0.8.5
roundcube webmail 0.4.1
roundcube webmail 0.5.1
roundcube webmail *
roundcube webmail 0.5.4
roundcube webmail 0.5
roundcube webmail 0.7
roundcube webmail 0.4
roundcube webmail 0.8.0
roundcube webmail 0.4.2
roundcube webmail 0.8.3
roundcube webmail 0.5.2
roundcube webmail 0.7.1
roundcube webmail 0.8.2
CVE-2013-5645 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in Roundcube webmail before 0.9.3 allow user-assisted remote attackers to inject arbitrary web script or HTML via the body of a message visited in (1) new or (2) draft mode, related to compose.inc; and (3) might allow remote authenticated users to inject arbitrary web script or HTML via an HTML signature, related to save_identity.inc.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
roundcube webmail 0.6
roundcube webmail 0.3.1
roundcube webmail 0.9.1
roundcube webmail 0.3
roundcube webmail 0.8.1
roundcube webmail 0.8.6
roundcube webmail 0.2.1
roundcube webmail 0.1
roundcube webmail 0.8.4
roundcube webmail 0.1.1
roundcube webmail 0.9
roundcube webmail 0.5.3
roundcube webmail 0.2.2
roundcube webmail 0.2
roundcube webmail 0.8.5
roundcube webmail 0.4.1
roundcube webmail 0.9.0
roundcube webmail 0.5.1
roundcube webmail *
roundcube webmail 0.5.4
roundcube webmail 0.7.2
roundcube webmail 0.5
roundcube webmail 0.7
roundcube webmail 0.4
roundcube webmail 0.8.0
roundcube webmail 0.4.2
roundcube webmail 0.8.3
roundcube webmail 0.5.2
roundcube webmail 0.7.1
roundcube webmail 0.7.3
roundcube webmail 0.8.2
CVE-2013-5646 LOW

Cross-site scripting (XSS) vulnerability in Roundcube webmail 1.0-git allows remote authenticated users to inject arbitrary web script or HTML via the Name field of an addressbook group.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
roundcube webmail 1.0
CVE-2013-6172 HIGH

steps/utils/save_pref.inc in Roundcube webmail before 0.8.7 and 0.9.x before 0.9.5 allows remote attackers to modify configuration settings via the _session parameter, which can be leveraged to read arbitrary files, conduct SQL injection attacks, and execute arbitrary code.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-89,

Products Affected

Vendor Product Version
roundcube webmail 0.6
roundcube webmail 0.3.1
roundcube webmail 0.9.1
roundcube webmail 0.3
roundcube webmail 0.8.1
roundcube webmail 0.2.1
roundcube webmail 0.1
roundcube webmail 0.8.4
roundcube webmail 0.9.2
roundcube webmail 0.1.1
roundcube webmail 0.9
roundcube webmail 0.5.3
roundcube webmail 0.2.2
roundcube webmail 0.2
roundcube webmail 0.8.5
roundcube webmail 0.4.1
roundcube webmail 0.9.0
roundcube webmail 0.5.1
roundcube webmail *
roundcube webmail 0.5.4
roundcube webmail 0.7.2
roundcube webmail 0.5
roundcube webmail 0.7
roundcube webmail 0.4
roundcube webmail 0.8.0
roundcube webmail 0.4.2
roundcube webmail 0.8.3
roundcube webmail 0.5.2
roundcube webmail 0.9.4
roundcube webmail 0.9.3
roundcube webmail 0.7.1
roundcube webmail 0.7.3
roundcube webmail 0.8.2
CVE-2014-9587 MEDIUM

Multiple cross-site request forgery (CSRF) vulnerabilities in Roundcube Webmail before 1.0.4 allow remote attackers to hijack the authentication of unspecified victims via unknown vectors, related to (1) address book operations or the (2) ACL or (3) Managesieve plugins.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
roundcube webmail *
CVE-2015-1433 MEDIUM

program/lib/Roundcube/rcube_washtml.php in Roundcube before 1.0.5 does not properly quote strings, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the style attribute in an email.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
fedoraproject fedora 21
roundcube webmail *
CVE-2015-2180 HIGH

The DBMail driver in the Password plugin in Roundcube before 1.1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the password.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-74,

Products Affected

Vendor Product Version
roundcube webmail *
CVE-2015-2181 MEDIUM

Multiple buffer overflows in the DBMail driver in the Password plugin in Roundcube before 1.1.0 allow remote attackers to have unspecified impact via the (1) password or (2) username.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
roundcube webmail *
CVE-2015-5381 MEDIUM

Cross-site scripting (XSS) vulnerability in program/include/rcmail.php in Roundcube Webmail 1.1.x before 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the _mbox parameter to the default URI.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
roundcube webmail 1.1
roundcube roundcube_webmail 1.1.1
CVE-2015-5382 MEDIUM

program/steps/addressbook/photo.inc in Roundcube Webmail before 1.0.6 and 1.1.x before 1.1.2 allows remote authenticated users to read arbitrary files via the _alt parameter when uploading a vCard.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
roundcube webmail 1.1
roundcube roundcube_webmail 1.1.1
roundcube roundcube_webmail *
CVE-2015-5383 MEDIUM

Roundcube Webmail 1.1.x before 1.1.2 allows remote attackers to obtain sensitive information by reading files in the (1) config, (2) temp, or (3) logs directory.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
roundcube webmail 1.1
roundcube roundcube_webmail 1.1.1
CVE-2015-8105 LOW

Cross-site scripting (XSS) vulnerability in program/js/app.js in Roundcube webmail before 1.0.7 and 1.1.x before 1.1.3 allows remote authenticated users to inject arbitrary web script or HTML via the file name in a drag-n-drop file upload.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
opensuse opensuse 13.1
roundcube webmail *
roundcube webmail 1.1.1
roundcube webmail 1.1.2
opensuse opensuse 13.2
roundcube webmail 1.1.0
CVE-2015-8770 MEDIUM

Directory traversal vulnerability in the set_skin function in program/include/rcmail_output_html.php in Roundcube before 1.0.8 and 1.1.x before 1.1.4 allows remote authenticated users with certain permissions to read arbitrary files or possibly execute arbitrary code via a .. (dot dot) in the _skin parameter to index.php.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-22,

Products Affected

Vendor Product Version
roundcube roundcube_webmail 1.1.0
roundcube roundcube_webmail 1.1.2
roundcube roundcube_webmail 1.1.1
roundcube roundcube_webmail *
roundcube roundcube_webmail 1.1.3
CVE-2015-8793 MEDIUM

Cross-site scripting (XSS) vulnerability in program/include/rcmail.php in Roundcube before 1.0.6 and 1.1.x before 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the _mbox parameter in a mail task to the default URL, a different vulnerability than CVE-2011-2937.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
roundcube webmail *
roundcube webmail 1.1.1
roundcube webmail 1.1.0
CVE-2015-8794 MEDIUM

Absolute path traversal vulnerability in program/steps/addressbook/photo.inc in Roundcube before 1.0.6 and 1.1.x before 1.1.2 allows remote authenticated users to read arbitrary files via a full pathname in the _alt parameter, related to contact photo handling.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-22,

Products Affected

Vendor Product Version
roundcube roundcube_webmail 1.1.0
roundcube roundcube_webmail 1.1.1
roundcube roundcube_webmail *
CVE-2015-8864 MEDIUM

Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.0.9 and 1.1.x before 1.1.5 allows remote attackers to inject arbitrary web script or HTML via a crafted SVG, a different vulnerability than CVE-2016-4068.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
roundcube webmail 1.1.4
opensuse leap 42.1
opensuse opensuse 13.1
roundcube webmail *
roundcube webmail 1.1
roundcube roundcube_webmail 1.1.2
roundcube roundcube_webmail 1.1.1
opensuse opensuse 13.2
roundcube roundcube_webmail 1.1.3
CVE-2016-4068 MEDIUM

Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.0.9 and 1.1.x before 1.1.5 allows remote attackers to inject arbitrary web script or HTML via a crafted SVG, a different vulnerability than CVE-2015-8864.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
roundcube webmail 1.1.4
opensuse leap 42.1
opensuse opensuse 13.1
roundcube webmail *
roundcube webmail 1.1
roundcube roundcube_webmail 1.1.2
roundcube roundcube_webmail 1.1.1
opensuse opensuse 13.2
roundcube roundcube_webmail 1.1.3
CVE-2016-4069 MEDIUM

Cross-site request forgery (CSRF) vulnerability in Roundcube Webmail before 1.1.5 allows remote attackers to hijack the authentication of users for requests that download attachments and cause a denial of service (disk consumption) via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
opensuse leap 42.1
roundcube webmail *
CVE-2016-4552 MEDIUM

Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.2.0 allows remote attackers to inject arbitrary web script or HTML via the href attribute in an area tag in an e-mail message.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
roundcube webmail 1.2
CVE-2016-9920 MEDIUM

steps/mail/sendmail.inc in Roundcube before 1.1.7 and 1.2.x before 1.2.3, when no SMTP server is configured and the sendmail program is enabled, does not properly restrict the use of custom envelope-from addresses on the sendmail command line, which allows remote authenticated users to execute arbitrary code via a modified HTTP request that sends a crafted e-mail message.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-284,

Products Affected

Vendor Product Version
roundcube webmail *
roundcube webmail 1.2.1
roundcube webmail 1.2.2
roundcube webmail 1.2.0
CVE-2017-16651 MEDIUM

Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's filesystem, including configuration files, as exploited in the wild in November 2017. The attacker must be able to authenticate at the target system with a valid username/password as the attack requires an active session. The issue is related to file-based attachment plugins and _task=settings&_action=upload-display&_from=timezone requests.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 1.8 5.9

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-552,CWE-552,

Products Affected

Vendor Product Version
roundcube webmail 1.2.4
roundcube webmail 1.2.5
debian debian_linux 7.0
roundcube webmail 1.3.0
roundcube webmail *
roundcube webmail 1.3.1
debian debian_linux 9.0
roundcube webmail 1.2.1
roundcube webmail 1.2.2
roundcube webmail 1.2.0
roundcube webmail 1.2.3
roundcube webmail 1.3.2
roundcube webmail 1.2.6
CVE-2017-17688 MEDIUM

The OpenPGP specification allows a Cipher Feedback Mode (CFB) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL. NOTE: third parties report that this is a problem in applications that mishandle the Modification Detection Code (MDC) feature or accept an obsolete packet type, not a problem in the OpenPGP specification

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
microsoft outlook 2007
mozilla thunderbird -
flipdogsolutions maildroid -
r2mail2 r2mail2 -
horde horde_imp -
roundcube webmail -
freron mailmate -
apple mail -
emclient emclient -
bloop airmail -
postbox-inc postbox -
CVE-2017-6820 MEDIUM

rcube_utils.php in Roundcube before 1.1.8 and 1.2.x before 1.2.4 is susceptible to a cross-site scripting vulnerability via a crafted Cascading Style Sheets (CSS) token sequence within an SVG element.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
roundcube webmail *
roundcube webmail 1.2.1
roundcube webmail 1.2.2
roundcube webmail 1.2.0
roundcube webmail 1.2.3
CVE-2017-8114 MEDIUM

Roundcube Webmail allows arbitrary password resets by authenticated users. This affects versions before 1.0.11, 1.1.x before 1.1.9, and 1.2.x before 1.2.5. The problem is caused by an improperly restricted exec call in the virtualmin and sasl drivers of the password plugin.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 8.8 HIGH CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 2.8 5.9

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-269,

Products Affected

Vendor Product Version
roundcube webmail *
CVE-2018-1000071 MEDIUM

roundcube version 1.3.4 and earlier contains an Insecure Permissions vulnerability in enigma plugin that can result in exfiltration of gpg private key. This attack appear to be exploitable via network connectivity.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-732,

Products Affected

Vendor Product Version
roundcube webmail *
CVE-2018-19205 MEDIUM

Roundcube before 1.3.7 mishandles GnuPG MDC integrity-protection warnings, which makes it easier for attackers to obtain sensitive information, a related issue to CVE-2017-17688. This is associated with plugins/enigma/lib/enigma_driver_gnupg.php.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
roundcube webmail *
CVE-2018-19206 MEDIUM

steps/mail/func.inc in Roundcube before 1.3.8 has XSS via crafted use of <svg><style>, as demonstrated by an onload attribute in a BODY element, within an HTML attachment.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
roundcube webmail *
debian debian_linux 9.0
CVE-2018-9846 MEDIUM

In Roundcube from versions 1.2.0 to 1.3.5, with the archive plugin enabled and configured, it's possible to exploit the unsanitized, user-controlled "_uid" parameter (in an archive.php _task=mail&_mbox=INBOX&_action=plugin.move2archive request) to perform an MX (IMAP) injection attack by placing an IMAP command after a %0d%0a sequence. NOTE: this is less easily exploitable in 1.3.4 and later because of a Same Origin Policy protection mechanism.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
roundcube webmail *
debian debian_linux 9.0
CVE-2019-10740 MEDIUM

In Roundcube Webmail before 1.3.10, an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub-parts within a crafted multipart email. The encrypted part(s) can further be hidden using HTML/CSS or ASCII newline characters. This modified multipart email can be re-sent by the attacker to the intended receiver. If the receiver replies to this (benign looking) email, they unknowingly leak the plaintext of the encrypted message part(s) back to the attacker.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 4.3 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N 2.8 1.4

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-319,

Products Affected

Vendor Product Version
opensuse leap 15.1
opensuse backports_sle 15.0
roundcube webmail *
opensuse leap 15.2
fedoraproject fedora 29
CVE-2019-15237 MEDIUM

Roundcube Webmail through 1.3.9 mishandles Punycode xn-- domain names, leading to homograph attacks.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.4 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N 2.8 4.0

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
roundcube webmail *
fedoraproject fedora 29
CVE-2020-12625 MEDIUM

An issue was discovered in Roundcube Webmail before 1.4.4. There is a cross-site scripting (XSS) vulnerability in rcube_washtml.php because JavaScript code can occur in the CDATA of an HTML message.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 6.1 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N 2.8 2.7

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
opensuse leap 15.1
opensuse backports_sle 15.0
roundcube webmail *
debian debian_linux 10.0
opensuse leap 15.2
debian debian_linux 9.0
CVE-2020-12626 MEDIUM

An issue was discovered in Roundcube Webmail before 1.4.4. A CSRF attack can cause an authenticated user to be logged out because POST was not considered.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 6.5 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H 2.8 3.6

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
roundcube webmail *
debian debian_linux 10.0
debian debian_linux 9.0
CVE-2020-12640 HIGH

Roundcube Webmail before 1.4.4 allows attackers to include local files and execute code via directory traversal in a plugin name to rcube_plugin_api.php.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 3.9 5.9

CVSS 2.0

Severity: HIGH

Problem Type: CWE-22,

Products Affected

Vendor Product Version
opensuse leap 15.1
opensuse backports_sle 15.0
roundcube webmail *
opensuse leap 15.2
CVE-2020-12641 HIGH

rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setting for im_convert_path or im_identify_path.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 3.9 5.9

CVSS 2.0

Severity: HIGH

Problem Type: CWE-78,CWE-78,

Products Affected

Vendor Product Version
opensuse leap 15.1
opensuse backports_sle 15.0
roundcube webmail *
opensuse leap 15.2
CVE-2020-13964 MEDIUM

An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. include/rcmail_output_html.php allows XSS via the username template object.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 6.1 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N 2.8 2.7

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
fedoraproject fedora 31
fedoraproject fedora 32
roundcube webmail *
debian debian_linux 10.0
debian debian_linux 9.0
CVE-2020-13965 MEDIUM

An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is among the allowed types for a preview.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 6.1 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N 2.8 2.7

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,CWE-80,

Products Affected

Vendor Product Version
fedoraproject fedora 31
fedoraproject fedora 32
roundcube webmail *
debian debian_linux 10.0
debian debian_linux 9.0
CVE-2020-15562 MEDIUM

An issue was discovered in Roundcube Webmail before 1.2.11, 1.3.x before 1.3.14, and 1.4.x before 1.4.7. It allows XSS via a crafted HTML e-mail message, as demonstrated by a JavaScript payload in the xmlns (aka XML namespace) attribute of a HEAD element when an SVG element exists.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
roundcube webmail *
debian debian_linux 10.0
CVE-2020-16145 MEDIUM

Roundcube Webmail before 1.3.15 and 1.4.8 allows stored XSS in HTML messages during message display via a crafted SVG document. This issue has been fixed in 1.4.8 and 1.3.15.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
fedoraproject fedora 31
fedoraproject fedora 32
roundcube webmail *
CVE-2020-18670 LOW

Cross Site Scripting (XSS) vulneraibility in Roundcube mail .4.4 via database host and user in /installer/test.php.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 5.4 MEDIUM CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N 2.3 2.7

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
roundcube webmail 1.4.4
CVE-2020-18671 LOW

Cross Site Scripting (XSS) vulnerability in Roundcube Mail <=1.4.4 via smtp config in /installer/test.php.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 5.4 MEDIUM CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N 2.3 2.7

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
roundcube webmail *
CVE-2020-35730 MEDIUM

An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attacker can send a plain text e-mail message, with JavaScript in a link reference element that is mishandled by linkref_addindex in rcube_string_replacer.php.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 6.1 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N 2.8 2.7

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,CWE-79,

Products Affected

Vendor Product Version
fedoraproject fedora 32
fedoraproject fedora 33
roundcube webmail *
debian debian_linux 9.0
CVE-2021-26925 LOW

Roundcube before 1.4.11 allows XSS via crafted Cascading Style Sheets (CSS) token sequences during HTML email rendering.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 5.4 MEDIUM CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N 2.3 2.7

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
fedoraproject fedora 32
fedoraproject fedora 33
roundcube webmail *
CVE-2021-44025 MEDIUM

Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to XSS in handling an attachment's filename extension when displaying a MIME type warning message.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 6.1 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N 2.8 2.7

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
fedoraproject fedora 34
fedoraproject fedora 33
roundcube webmail *
debian debian_linux 10.0
debian debian_linux 9.0
debian debian_linux 11.0
CVE-2021-44026 HIGH

Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 3.9 5.9

CVSS 2.0

Severity: HIGH

Problem Type: CWE-89,CWE-89,

Products Affected

Vendor Product Version
fedoraproject fedora 34
fedoraproject fedora 33
roundcube webmail *
debian debian_linux 10.0
debian debian_linux 9.0
debian debian_linux 11.0
CVE-2021-46144 MEDIUM

Roundcube before 1.4.13 and 1.5.x before 1.5.2 allows XSS via an HTML e-mail message with crafted Cascading Style Sheets (CSS) token sequences.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 6.1 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N 2.8 2.7

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
debian debian_linux 10.0
roundcube roundcube *
debian debian_linux 9.0
debian debian_linux 11.0
CVE-2023-43770

Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of program/lib/Roundcube/rcube_string_replacer.php behavior.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 6.1 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N 2.8 2.7

Products Affected

Vendor Product Version
roundcube webmail *
debian debian_linux 10.0
CVE-2023-47272

Roundcube 1.5.x before 1.5.6 and 1.6.x before 1.6.5 allows XSS via a Content-Type or Content-Disposition header (used for attachment preview or download).

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 6.1 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N 2.8 2.7
cve@mitre.org 6.1 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N 2.8 2.7

Products Affected

Vendor Product Version
fedoraproject fedora 39
fedoraproject fedora 37
debian debian_linux 12.0
roundcube webmail *
debian debian_linux 10.0
debian debian_linux 11.0
fedoraproject fedora 38
CVE-2023-5631

Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a crafted SVG document because of program/lib/Roundcube/rcube_washtml.php behavior. This could allow a remote attacker to load arbitrary JavaScript code.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
security@eset.com 6.1 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N 2.8 2.7
nvd@nist.gov 5.4 MEDIUM CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N 2.3 2.7

Products Affected

Vendor Product Version
fedoraproject fedora 39
debian debian_linux 12.0
roundcube webmail *
debian debian_linux 10.0
debian debian_linux 11.0
CVE-2024-37383

Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.

Products Affected

Vendor Product Version
roundcube webmail *
debian debian_linux 10.0
CVE-2024-37384

Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via list columns from user preferences.

Products Affected

Vendor Product Version
roundcube webmail *
debian debian_linux 10.0
CVE-2024-37385

Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 on Windows allows command injection via im_convert_path and im_identify_path. NOTE: this issue exists because of an incomplete fix for CVE-2020-12641.

Products Affected

Vendor Product Version
roundcube webmail *
CVE-2024-42009

A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a crafted e-mail message that abuses a Desanitization issue in message_body() in program/actions/mail/show.php.

Products Affected

Vendor Product Version
roundcube webmail *
CVE-2024-57004

Cross-Site Scripting (XSS) vulnerability in Roundcube Webmail 1.6.9 allows remote authenticated users to upload a malicious file as an email attachment, leading to the triggering of the XSS by visiting the SENT session.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
134c704f-9b21-4f2e-91b3-4a467353bcc0 6.1 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N 2.8 2.7

Products Affected

Vendor Product Version
roundcube webmail 1.6.9
CVE-2025-49113

Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP Object Deserialization.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
cve@mitre.org 9.9 CRITICAL CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H 3.1 6.0

Products Affected

Vendor Product Version
roundcube webmail *
debian debian_linux 11.0
CVE-2025-68460

Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a information disclosure vulnerability in the HTML style sanitizer.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
cve@mitre.org 7.2 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N 3.9 2.7

Products Affected

Vendor Product Version
roundcube webmail *
CVE-2025-68461

Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
cve@mitre.org 7.2 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N 3.9 2.7

Products Affected

Vendor Product Version
roundcube webmail *
CVE-2026-35538

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsanitized IMAP SEARCH command arguments could lead to IMAP injection or CSRF bypass during mail search.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
cve@mitre.org 3.1 LOW CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N 1.6 1.4

Products Affected

Vendor Product Version
roundcube webmail *
CVE-2026-35539

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. XSS exists because of insufficient HTML attachment sanitization in preview mode. A victim must preview a text/html attachment.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
cve@mitre.org 6.1 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N 2.8 2.7

Products Affected

Vendor Product Version
roundcube webmail *
CVE-2026-35540

An issue was discovered in Roundcube Webmail 1.6.0 before 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
cve@mitre.org 5.4 MEDIUM CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N 2.2 2.7

Products Affected

Vendor Product Version
roundcube webmail *
CVE-2026-35541

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Incorrect password comparison in the password plugin could lead to type confusion that allows a password change without knowing the old password.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
cve@mitre.org 4.2 MEDIUM CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N 1.6 2.5

Products Affected

Vendor Product Version
roundcube webmail *
CVE-2026-35542

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via a crafted background attribute of a BODY element in an e-mail message. This may lead to information disclosure or access-control bypass.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
cve@mitre.org 5.3 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N 3.9 1.4

Products Affected

Vendor Product Version
roundcube webmail *
CVE-2026-35543

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via SVG content (with animate attributes) in an e-mail message. This may lead to information disclosure or access-control bypass.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
cve@mitre.org 5.3 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N 3.9 1.4

Products Affected

Vendor Product Version
roundcube webmail *
CVE-2026-35544

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to a fixed-position mitigation bypass via the use of !important.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
cve@mitre.org 5.3 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N 3.9 1.4

Products Affected

Vendor Product Version
roundcube webmail *
CVE-2026-35545

An issue was discovered in Roundcube Webmail before 1.5.15 and 1.6.15. The remote image blocking feature can be bypassed via SVG content in an e-mail message. This may lead to information disclosure or access-control bypass. This involves the animate element with attributeName=fill/filter/stroke.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
cve@mitre.org 5.3 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N 3.9 1.4

Products Affected

Vendor Product Version
roundcube webmail *