Roundcube Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for Roundcube products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

12

In CISA KEV

11

Beyond CISA KEV

1

Sensor Observed

0

Virtual Patch Available

0

Roundcube KEVs Added by Year

Loading...

12 Roundcube KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2025-68461

Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document.

Confirmed In CISA 01 Jun 2026
CVE-2025-49113

Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is...

Confirmed In CISA 01 Jun 2026
CVE-2024-42009

A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a...

Confirmed In CISA 01 Jun 2026
CVE-2013-1904

Absolute path traversal vulnerability in steps/mail/sendmail.inc in Roundcube Webmail before 0.7.3 and 0.8.x before 0.8.6 allows remote attackers...

High Not in CISA 08 Feb 2014
CVE-2017-16651

Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's filesystem,...

Confirmed In CISA 03 Nov 2021
CVE-2021-44026

Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.

Confirmed In CISA 22 Jun 2023
CVE-2020-12641

rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setting...

Confirmed In CISA 22 Jun 2023
CVE-2020-35730

An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attacker can send a plain text...

Confirmed In CISA 22 Jun 2023
CVE-2023-5631

Stored XSS vulnerability in Roundcube

Confirmed In CISA 26 Oct 2023
CVE-2023-43770

Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of...

Confirmed In CISA 12 Feb 2024
CVE-2020-13965

An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is...

Confirmed In CISA 26 Jun 2024
CVE-2024-37383

Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.

Confirmed In CISA 24 Oct 2024

Common Vulnerability Classes (CWE)

  • CWE-79 — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') 6
  • CWE-502 — Deserialization of Untrusted Data 1
  • CWE-552 — Files or Directories Accessible to External Parties 1
  • CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 1
  • CWE-80 — Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) 1
  • CWE-89 — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 1
  • CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology