Export CSV

Products

1 vendor
VendorProductsCVEsKEVAvg EPSSWorst Severity
224658.5%CRITICAL

Related CVEs

24
CVE IDDescriptionSeverityCVSSKEVEPSSPublished
CVE-2026-35545An issue was discovered in Roundcube Webmail before 1.5.15 and 1.6.15. The remote image blocking feature can be bypassed via SVG content in an e-mail message. This may lead to information disclosure or access-control bypass. This involves the animate element with attributeName=fill/filter/stroke.HIGH8.224.7%Apr 3, 2026
CVE-2026-35544An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to a fixed-position mitigation bypass via the use of !important.MEDIUM5.328.5%Apr 3, 2026
CVE-2026-35543An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via SVG content (with animate attributes) in an e-mail message. This may lead to information disclosure or access-control bypass.MEDIUM5.332.1%Apr 3, 2026
CVE-2026-35542An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via a crafted background attribute of a BODY element in an e-mail message. This may lead to information disclosure or access-control bypass.MEDIUM5.332.1%Apr 3, 2026
CVE-2026-35541An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Incorrect password comparison in the password plugin could lead to type confusion that allows a password change without knowing the old password.MEDIUM4.215.3%Apr 3, 2026
CVE-2026-35540An issue was discovered in Roundcube Webmail 1.6.0 before 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts.MEDIUM6.522.8%Apr 3, 2026
CVE-2026-35539An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. XSS exists because of insufficient HTML attachment sanitization in preview mode. A victim must preview a text/html attachment.MEDIUM6.116.3%Apr 3, 2026
CVE-2026-35538An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsanitized IMAP SEARCH command arguments could lead to IMAP injection or CSRF bypass during mail search.LOW3.120.0%Apr 3, 2026
CVE-2026-35537An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsafe deserialization in the redis/memcache session handler may lead to arbitrary file write operations by unauthenticated attackers via crafted session data.HIGH7.537.5%Apr 3, 2026
CVE-2025-68461Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document.MEDIUM6.1KEV97.1%Dec 18, 2025
CVE-2025-68460Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a information disclosure vulnerability in the HTML style sanitizer.HIGH7.515.5%Dec 18, 2025
CVE-2025-49113Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP Object Deserialization.HIGH8.8KEV99.8%Jun 2, 2025
CVE-2024-57004Cross-Site Scripting (XSS) vulnerability in Roundcube Webmail 1.6.9 allows remote authenticated users to upload a malicious file as an email attachment, leading to the triggering of the XSS by visiting the SENT session.MEDIUM6.197.8%Feb 3, 2025
CVE-2024-42009A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a crafted e-mail message that abuses a Desanitization issue in message_body() in program/actions/mail/show.php.CRITICAL9.3KEV99.6%Aug 5, 2024
CVE-2024-42008A Cross-Site Scripting vulnerability in rcmail_action_mail_get->run() in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a malicious e-mail attachment served with a dangerous Content-Type header.CRITICAL9.398.1%Aug 5, 2024
CVE-2024-37385Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 on Windows allows command injection via im_convert_path and im_identify_path. NOTE: this issue exists because of an incomplete fix for CVE-2020-12641.CRITICAL9.870.6%Jun 7, 2024
CVE-2024-37384Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via list columns from user preferences.MEDIUM6.138.9%Jun 7, 2024
CVE-2024-37383Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.MEDIUM6.1KEV99.4%Jun 7, 2024
CVE-2023-47272Roundcube 1.5.x before 1.5.6 and 1.6.x before 1.6.5 allows XSS via a Content-Type or Content-Disposition header (used for attachment preview or download).MEDIUM6.146.1%Nov 6, 2023
CVE-2023-5631Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a crafted SVG document because of program/lib/Roundcube/rcube_washtml.php behavior. This could allow a remote attacker to load arbitrary JavaScript code.MEDIUM5.4KEV99.4%Oct 18, 2023