Vulnerabilities (CVE)

Filtered by vendor Roundcube Subscribe
Total 98 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-75003 1 Roundcube 1 Webmail 2026-09-10 N/A 5.8 MEDIUM
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed url() in a FuncIRI attribute of an SVG image could evade the remote image blocking, which may lead to information disclosure or privilege escalation.
CVE-2026-75000 1 Roundcube 1 Webmail 2026-09-08 N/A 5.8 MEDIUM
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper HTML/CSS sanitization of the SVG animate "by" attribute may lead to remote image blocking bypass, which in turn may lead to information disclosure or privilege escalation.
CVE-2026-74999 1 Roundcube 1 Webmail 2026-09-08 N/A 5.4 MEDIUM
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the "Add to address book" action was subject to stored XSS.
CVE-2026-74998 1 Roundcube 1 Webmail 2026-09-08 N/A 7.2 HIGH
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, responses from the CSS (Cascading Style Sheets) proxy were not validated, which may result in information disclosure or XSS (cross-site scripting) via MIME sniffing.
CVE-2026-74997 1 Roundcube 1 Webmail 2026-09-08 N/A 8.8 HIGH
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the cmd_learn driver of the markasjunk plugin is subject to remote code execution via crafted placeholder replacement values. This issue only affects Roundcube instances using the markasjunk plugin with its cmd_learn driver.
CVE-2026-75002 1 Roundcube 1 Webmail 2026-09-08 N/A 7.1 HIGH
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, mail search and LITERAL+ byte-count desynchronization could lead to information disclosure or privilege escalation via IMAP command injection.
CVE-2026-75004 1 Roundcube 1 Webmail 2026-09-08 N/A 4.3 MEDIUM
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper rule name quoting could lead to managesieve_disabled_actions setting bypass via a crafted rule name in a Sieve script. This issue only affects Roundcube instances using the managesieve plugin.
CVE-2026-75006 1 Roundcube 1 Webmail 2026-09-08 N/A 5.8 MEDIUM
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. This issue exists because of insufficient fixes for CVE-2026-35540, CVE-2026-48843 and CVE-2026-62643.
CVE-2026-75007 1 Roundcube 1 Webmail 2026-09-08 N/A 5.4 MEDIUM
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the LDAP search filter was subject to injection via unescaped %u/%fu/%d substitution, which may lead to information disclosure or privilege escalation.
CVE-2026-75010 1 Roundcube 1 Webmail 2026-09-08 N/A 6.4 MEDIUM
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the modoboa driver of the password plugin could leak a Modoboa API authentication token to a user-controlled host via crafted session data. This issue only affects Roundcube instances using the password plugin with its modoboa driver.
CVE-2026-35543 1 Roundcube 1 Webmail 2026-07-24 N/A 5.3 MEDIUM
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via SVG content (with animate attributes) in an e-mail message. This may lead to information disclosure or access-control bypass.
CVE-2026-35537 1 Roundcube 1 Webmail 2026-07-24 N/A 3.7 LOW
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsafe deserialization in the redis/memcache session handler may lead to arbitrary file write operations by unauthenticated attackers via crafted session data.
CVE-2026-35538 1 Roundcube 1 Webmail 2026-07-24 N/A 3.1 LOW
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsanitized IMAP SEARCH command arguments could lead to IMAP injection or CSRF bypass during mail search.
CVE-2026-35542 1 Roundcube 1 Webmail 2026-07-24 N/A 5.3 MEDIUM
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via a crafted background attribute of a BODY element in an e-mail message. This may lead to information disclosure or access-control bypass.
CVE-2026-35539 1 Roundcube 1 Webmail 2026-07-24 N/A 6.1 MEDIUM
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. XSS exists because of insufficient HTML attachment sanitization in preview mode. A victim must preview a text/html attachment.
CVE-2026-35544 1 Roundcube 1 Webmail 2026-07-24 N/A 5.3 MEDIUM
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to a fixed-position mitigation bypass via the use of !important.
CVE-2026-35541 1 Roundcube 1 Webmail 2026-07-24 N/A 4.2 MEDIUM
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Incorrect password comparison in the password plugin could lead to type confusion that allows a password change without knowing the old password.
CVE-2026-35545 1 Roundcube 1 Webmail 2026-07-24 N/A 5.3 MEDIUM
An issue was discovered in Roundcube Webmail before 1.5.15 and 1.6.15. The remote image blocking feature can be bypassed via SVG content in an e-mail message. This may lead to information disclosure or access-control bypass. This involves the animate element with attributeName=fill/filter/stroke.
CVE-2026-35540 1 Roundcube 1 Webmail 2026-07-24 N/A 5.4 MEDIUM
An issue was discovered in Roundcube Webmail 1.6.0 before 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts.
CVE-2026-62641 1 Roundcube 1 Webmail 2026-07-20 N/A 4.3 MEDIUM
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the TNEF decoder was subject to denial of service via a crafted compressed-RTF size.