Roundcube Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for Roundcube products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
12
In CISA KEV
11
Beyond CISA KEV
1
Sensor Observed
0
Virtual Patch Available
0
Roundcube KEVs Added by Year
12 Roundcube KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2025-68461
Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document. |
Webmail | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2025-49113
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is... |
Webmail | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2024-42009
A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a... |
Roundcube Webmail | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2013-1904
Absolute path traversal vulnerability in steps/mail/sendmail.inc in Roundcube Webmail before 0.7.3 and 0.8.x before 0.8.6 allows remote attackers... |
Webmail | High | Not in CISA | 08 Feb 2014 |
|
CVE-2017-16651
Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's filesystem,... |
Roundcube Webmail | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2021-44026
Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params. |
Roundcube Webmail | Confirmed | In CISA | 22 Jun 2023 |
|
CVE-2020-12641
rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setting... |
Webmail | Confirmed | In CISA | 22 Jun 2023 |
|
CVE-2020-35730
An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attacker can send a plain text... |
Webmail | Confirmed | In CISA | 22 Jun 2023 |
|
CVE-2023-5631
Stored XSS vulnerability in Roundcube |
Roundcubemail | Confirmed | In CISA | 26 Oct 2023 |
|
CVE-2023-43770
Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of... |
Roundcube Webmail | Confirmed | In CISA | 12 Feb 2024 |
|
CVE-2020-13965
An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is... |
Webmail | Confirmed | In CISA | 26 Jun 2024 |
|
CVE-2024-37383
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes. |
Roundcube Webmail | Confirmed | In CISA | 24 Oct 2024 |
Common Vulnerability Classes (CWE)
- CWE-79 — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') 6
- CWE-502 — Deserialization of Untrusted Data 1
- CWE-552 — Files or Directories Accessible to External Parties 1
- CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 1
- CWE-80 — Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) 1
- CWE-89 — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 1
- CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 1
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology