Roundcube 漏洞与 CVE 列表(83)

产品(CPE): — CVE 数: 83

Roundcube 漏洞概览

汇总 Roundcube 相关全部产品的 CVE 与安全漏洞情报,包括 CVSS、EPSS、公开时间与漏洞情报数据。

已披露问题常与 跨站脚本、路径处理缺陷与CSRF 相关,可能在 软件部署与生产负载 场景中带来 应用崩溃与内存损坏 等暴露风险。

相关漏洞数据主要来源于公开漏洞披露与安全公告,可用于评估历史漏洞暴露面与修复优先级。

漏洞分布趋势(近 24 个月)

显示 12083 CVE 数
«« 第一页 « 上一页 第 1 / 5 页 下一页 »
CVE 摘要 来源 最高 CVSS EPSS % 公开时间 更新时间
CVE-2026-35545 An issue was discovered in Roundcube Webmail before 1.5.15 and 1.6.15. The remote image blocking feature can be bypassed via SVG content in an e-mail message. This may lead to information disclosure or access-control bypass. This involves the animate element with attributeName=fill/filter/stroke. [email protected] 5.3 0.05% 2026-04-03 2026-04-07
CVE-2026-35544 An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to a fixed-position mitigation bypass via the use of !important. [email protected] 5.3 0.03% 2026-04-03 2026-04-09
CVE-2026-35543 An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via SVG content (with animate attributes) in an e-mail message. This may lead to information disclosure or access-control bypass. [email protected] 5.3 0.03% 2026-04-03 2026-04-07
CVE-2026-35542 An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via a crafted background attribute of a BODY element in an e-mail message. This may lead to information disclosure or access-control bypass. [email protected] 5.3 0.03% 2026-04-03 2026-04-07
CVE-2026-35541 An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Incorrect password comparison in the password plugin could lead to type confusion that allows a password change without knowing the old password. [email protected] 4.2 0.03% 2026-04-03 2026-04-07
CVE-2026-35540 An issue was discovered in Roundcube Webmail 1.6.0 before 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. [email protected] 5.4 0.02% 2026-04-03 2026-04-07
CVE-2026-35539 An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. XSS exists because of insufficient HTML attachment sanitization in preview mode. A victim must preview a text/html attachment. [email protected] 6.1 0.04% 2026-04-03 2026-04-07
CVE-2026-35538 An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsanitized IMAP SEARCH command arguments could lead to IMAP injection or CSRF bypass during mail search. [email protected] 3.1 0.04% 2026-04-03 2026-04-07
CVE-2026-35537 An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsafe deserialization in the redis/memcache session handler may lead to arbitrary file write operations by unauthenticated attackers via crafted session data. [email protected] 3.7 0.05% 2026-04-03 2026-04-13
CVE-2025-68461 KEV Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document. [email protected] 7.2 6.86% 2025-12-18 2026-02-23
CVE-2025-68460 Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a information disclosure vulnerability in the HTML style sanitizer. [email protected] 7.2 0.04% 2025-12-18 2026-01-02
CVE-2025-49113 KEV Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP Object Deserialization. [email protected] 9.9 90.47% 2025-06-02 2026-02-23
CVE-2024-57004 Cross-Site Scripting (XSS) vulnerability in Roundcube Webmail 1.6.9 allows remote authenticated users to upload a malicious file as an email attachment, leading to the triggering of the XSS by visiting the SENT session. [email protected] 6.1 4.20% 2025-02-03 2025-12-22
CVE-2024-42009 KEV A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a crafted e-mail message that abuses a Desanitization issue in message_body() in program/actions/mail/show.php. [email protected] 9.3 91.41% 2024-08-05 2025-11-04
CVE-2024-42008 A Cross-Site Scripting vulnerability in rcmail_action_mail_get->run() in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a malicious e-mail attachment served with a dangerous Content-Type header. [email protected] 9.3 50.95% 2024-08-05 2025-03-13
CVE-2024-37385 Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 on Windows allows command injection via im_convert_path and im_identify_path. NOTE: this issue exists because of an incomplete fix for CVE-2020-12641. [email protected] 9.8 0.83% 2024-06-07 2026-02-06
CVE-2024-37384 Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via list columns from user preferences. [email protected] 6.1 0.53% 2024-06-07 2025-05-01
CVE-2024-37383 KEV Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes. [email protected] 6.1 64.03% 2024-06-07 2025-10-31
CVE-2023-47272 Roundcube 1.5.x before 1.5.6 and 1.6.x before 1.6.5 allows XSS via a Content-Type or Content-Disposition header (used for attachment preview or download). [email protected] 6.1 0.50% 2023-11-06 2024-11-21
CVE-2023-5631 KEV Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a crafted SVG document because of program/lib/Roundcube/rcube_washtml.php behavior. This could allow a remote attacker to load arbitrary JavaScript code. [email protected] 6.1 83.23% 2023-10-18 2025-10-30
«« 第一页 « 上一页 第 1 / 5 页 下一页 »
cvelogic Threat Intelligence