Aggregates CVE and security vulnerability intelligence across all Roundcube-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.
Historical issues mainly involve vendor risk input validation, vendor risk ssrf, and vendor risk file inclusion and related problems; some flaws may lead to vendor impact application crash and vendor impact memory corruption.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2026-54433 | In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafted plain-text email message. The attacker-controlled JavaScript executes within the victim's authenticated session simply by opening or previewing the message (zero-click). | [email protected] | 7.2 | 0.28% | 2026-07-14 | 2026-07-17 |
| CVE-2026-54432 | Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2 allows Stored Cross-Site Scripting (XSS). The issue occurs because the attachment MIME type is not properly escaped on the attachment-validation warning page. | [email protected] | 4.7 | 0.21% | 2026-07-14 | 2026-07-15 |
| CVE-2026-62644 | In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing via session data, which could lead to account takeover. | [email protected] | 6.4 | 0.26% | 2026-07-14 | 2026-07-20 |
| CVE-2026-62643 | In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. NOTE: this issue exists because of insufficient fixes for CVE-2026-35540 and CVE-2026-48843. | [email protected] | 7.2 | 0.22% | 2026-07-14 | 2026-07-20 |
| CVE-2026-62642 | In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, an infinite loop was discovered in the TNEF decoder, which may lead to denial of service upon opening an email with a TNEF attachment. | [email protected] | 4.3 | 0.26% | 2026-07-14 | 2026-07-20 |
| CVE-2026-62641 | In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the TNEF decoder was subject to denial of service via a crafted compressed-RTF size. | [email protected] | 4.3 | 0.26% | 2026-07-14 | 2026-07-20 |
| CVE-2026-48849 | In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, an unsanitized subject field in the draft restored value could lead to stored XSS/HTML/CSS injection on shared mailboxes. | [email protected] | 4.4 | 0.19% | 2026-05-25 | 2026-06-17 |
| CVE-2026-48848 | Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7 has insufficient HTML sanitization that could lead to Cascading Style Sheets (CSS) injection via an SVG document that has an animate element with the attributeName attribute. | [email protected] | 7.2 | 0.39% | 2026-05-25 | 2026-06-17 |
| CVE-2026-48847 | Roundcube Webmail 1.6.x before 1.6.16, and 1.7.x before 1.7.1 allows pre-authentication arbitrary file deletion via redis/memcache session poisoning bypass. | [email protected] | 3.7 | 0.40% | 2026-05-25 | 2026-06-17 |
| CVE-2026-48846 | In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, the remote image blocking feature can be bypassed via a crafted CSS var() value in an e-mail message, which may lead to information disclosure or access-control bypass. | [email protected] | 6.5 | 0.40% | 2026-05-25 | 2026-06-17 |
| CVE-2026-48845 | In Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16 and 1.7.x before 1.7.1, remote image blocking was not honored for URLs pointing to local/private destinations, which may lead to information disclosure or privilege escalation via a text/html email message. | [email protected] | 6.5 | 0.38% | 2026-05-25 | 2026-06-17 |
| CVE-2026-48844 | Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has insecure code evaluation logic in LDAP the autovalues option that could lead to code injection. (Support for code evaluation has been removed in 1.6.16 and 1.7.1.) | [email protected] | 7.5 | 0.37% | 2026-05-25 | 2026-06-17 |
| CVE-2026-48843 | Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16,and 1.7.x before 1.7.1 has Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. The issue stems from an insufficient fix for CVE-2026-35540. | [email protected] | 7.2 | 0.27% | 2026-05-25 | 2026-06-17 |
| CVE-2026-48842 | Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via a preg_replace() backslash escape bypass. | [email protected] | 8.1 | 0.76% | 2026-05-25 | 2026-06-17 |
| CVE-2026-35545 | An issue was discovered in Roundcube Webmail before 1.5.15 and 1.6.15. The remote image blocking feature can be bypassed via SVG content in an e-mail message. This may lead to information disclosure or access-control bypass. This involves the animate element with attributeName=fill/filter/stroke. | [email protected] | 5.3 | 0.33% | 2026-04-03 | 2026-06-17 |
| CVE-2026-35544 | An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to a fixed-position mitigation bypass via the use of !important. | [email protected] | 5.3 | 0.37% | 2026-04-03 | 2026-06-17 |
| CVE-2026-35543 | An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via SVG content (with animate attributes) in an e-mail message. This may lead to information disclosure or access-control bypass. | [email protected] | 5.3 | 0.40% | 2026-04-03 | 2026-06-17 |
| CVE-2026-35542 | An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via a crafted background attribute of a BODY element in an e-mail message. This may lead to information disclosure or access-control bypass. | [email protected] | 5.3 | 0.40% | 2026-04-03 | 2026-06-17 |
| CVE-2026-35541 | An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Incorrect password comparison in the password plugin could lead to type confusion that allows a password change without knowing the old password. | [email protected] | 4.2 | 0.24% | 2026-04-03 | 2026-06-17 |
| CVE-2026-35540 | An issue was discovered in Roundcube Webmail 1.6.0 before 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. | [email protected] | 5.4 | 0.31% | 2026-04-03 | 2026-06-17 |