Roundcube
Roundcube Webmail: vulnerabilidades y CVE
Roundcube Webmail tiene 106 vulnerabilidades publicadas, 37 de ellas en los últimos 12 meses. 10 son críticas y 11 figuran en el catálogo de explotación activa de CISA.
CVE106
Últimos 12 meses37
Críticas10
Explotadas activamente11
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-68461 | Media (6.1) | 27% | ⚠ Explotación activa | 18 dic 2025 | Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document. |
| CVE-2025-49113 | Alta (8.8) | 99% | ⚠ Explotación activa | 2 jun 2025 | Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP… |
| CVE-2024-42009 | Crítica (9.3) | 83% | ⚠ Explotación activa | 5 ago 2024 | A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a crafted e-mail message that abuses a Desanitization issue in… |
| CVE-2024-37383 | Media (6.1) | 73% | ⚠ Explotación activa | 7 jun 2024 | Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes. |
| CVE-2020-13965 | Media (6.1) | 77% | ⚠ Explotación activa | 9 jun 2020 | An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is among the allowed types for a preview. |
| CVE-2023-43770 | Media (6.1) | 64% | ⚠ Explotación activa | 22 sept 2023 | Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of program/lib/Roundcube/rcube_string_replacer.php behavior. |
| CVE-2023-5631 | Media (5.4) | 76% | ⚠ Explotación activa | 18 oct 2023 | Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a crafted SVG document because of program/lib/Roundcube/rcube_washtml.php behavior. This could allow… |
| CVE-2021-44026 | Crítica (9.8) | 70% | ⚠ Explotación activa | 19 nov 2021 | Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params. |
| CVE-2020-12641 | Crítica (9.8) | 84% | ⚠ Explotación activa | 4 may 2020 | rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setting for im_convert_path or im_identify_path. |
| CVE-2020-35730 | Media (6.1) | 33% | ⚠ Explotación activa | 28 dic 2020 | An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attacker can send a plain text e-mail message, with JavaScript in a link reference element that is… |
| CVE-2017-16651 | Alta (7.8) | 46% | ⚠ Explotación activa | 9 nov 2017 | Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's filesystem, including configuration files, as exploited in the wild in November… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-75010 | Media (4.3) | 0.39% | — | 17 ago 2026 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the modoboa driver of the password plugin could leak a Modoboa API authentication token to a user-controlled host via crafted session data. This issue only… |
| CVE-2026-75007 | Alta (8.8) | 0.50% | — | 17 ago 2026 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the LDAP search filter was subject to injection via unescaped %u/%fu/%d substitution, which may lead to information disclosure or privilege escalation. |
| CVE-2026-75006 | Media (5.8) | 0.56% | — | 17 ago 2026 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to… |
| CVE-2026-75004 | Media (4.3) | 0.37% | — | 17 ago 2026 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper rule name quoting could lead to managesieve_disabled_actions setting bypass via a crafted rule name in a Sieve script. This issue only affects… |
| CVE-2026-75003 | Crítica (9.8) | 0.58% | — | 17 ago 2026 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed url() in a FuncIRI attribute of an SVG image could evade the remote image blocking, which may lead to information disclosure or privilege escalation. |
| CVE-2026-75002 | Alta (7.1) | 2.3% | — | 17 ago 2026 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, mail search and LITERAL+ byte-count desynchronization could lead to information disclosure or privilege escalation via IMAP command injection. |
| CVE-2026-75000 | Media (5.8) | 0.47% | — | 17 ago 2026 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper HTML/CSS sanitization of the SVG animate "by" attribute may lead to remote image blocking bypass, which in turn may lead to information disclosure or… |
| CVE-2026-74999 | Media (5.4) | 0.30% | — | 17 ago 2026 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the "Add to address book" action was subject to stored XSS. |
| CVE-2026-74998 | Alta (7.2) | 0.44% | — | 17 ago 2026 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, responses from the CSS (Cascading Style Sheets) proxy were not validated, which may result in information disclosure or XSS (cross-site scripting) via MIME… |
| CVE-2026-74997 | Alta (8.8) | 1.1% | — | 17 ago 2026 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the cmd_learn driver of the markasjunk plugin is subject to remote code execution via crafted placeholder replacement values. This issue only affects Roundcube… |
| CVE-2026-54433 | Crítica (10) | 0.31% | — | 14 jul 2026 | In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafted plain-text email message. The attacker-controlled JavaScript executes within the victim's authenticated… |
| CVE-2026-54432 | Media (4.7) | 0.21% | — | 14 jul 2026 | Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2 allows Stored Cross-Site Scripting (XSS). The issue occurs because the attachment MIME type is not properly escaped on the attachment-validation warning page. |
| CVE-2026-62644 | Crítica (9.8) | 0.50% | — | 14 jul 2026 | In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing via session data, which could lead to account takeover. |
| CVE-2026-62643 | Crítica (10) | 0.44% | — | 14 jul 2026 | In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to… |
| CVE-2026-62642 | Media (6.5) | 0.52% | — | 14 jul 2026 | In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, an infinite loop was discovered in the TNEF decoder, which may lead to denial of service upon opening an email with a TNEF attachment. |
| CVE-2026-62641 | Media (6.5) | 0.47% | — | 14 jul 2026 | In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the TNEF decoder was subject to denial of service via a crafted compressed-RTF size. |
| CVE-2026-48849 | Media (4.4) | 0.26% | — | 25 may 2026 | In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, an unsanitized subject field in the draft restored value could lead to stored XSS/HTML/CSS injection on shared mailboxes. |
| CVE-2026-48848 | Alta (7.2) | 0.45% | — | 25 may 2026 | Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7 has insufficient HTML sanitization that could lead to Cascading Style Sheets (CSS) injection via an SVG document that has an animate element with the… |
| CVE-2026-48847 | Baja (3.7) | 0.54% | — | 25 may 2026 | Roundcube Webmail 1.6.x before 1.6.16, and 1.7.x before 1.7.1 allows pre-authentication arbitrary file deletion via redis/memcache session poisoning bypass. |
| CVE-2026-48846 | Media (6.5) | 0.48% | — | 25 may 2026 | In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, the remote image blocking feature can be bypassed via a crafted CSS var() value in an e-mail message, which may lead to information disclosure or… |
| CVE-2026-48845 | Media (6.5) | 0.45% | — | 25 may 2026 | In Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16 and 1.7.x before 1.7.1, remote image blocking was not honored for URLs pointing to local/private destinations, which may lead to information disclosure or privilege… |
| CVE-2026-48844 | Alta (7.5) | 0.51% | — | 25 may 2026 | Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has insecure code evaluation logic in LDAP the autovalues option that could lead to code injection. (Support for code evaluation has been removed in 1.6.16… |
| CVE-2026-48843 | Alta (7.2) | 0.46% | — | 25 may 2026 | Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16,and 1.7.x before 1.7.1 has Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet… |
| CVE-2026-48842 | Alta (8.1) | 0.89% | — | 25 may 2026 | Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via a preg_replace() backslash escape bypass. |
| CVE-2026-35545 | Alta (8.2) | 0.55% | — | 3 abr 2026 | An issue was discovered in Roundcube Webmail before 1.5.15 and 1.6.15. The remote image blocking feature can be bypassed via SVG content in an e-mail message. This may lead to information disclosure or access-control… |
| CVE-2026-35544 | Media (5.3) | 0.51% | — | 3 abr 2026 | An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to a fixed-position mitigation bypass via the use of… |
| CVE-2026-35543 | Media (5.3) | 0.53% | — | 3 abr 2026 | An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via SVG content (with animate attributes) in an e-mail message. This may lead to information… |
| CVE-2026-35542 | Media (5.3) | 0.53% | — | 3 abr 2026 | An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via a crafted background attribute of a BODY element in an e-mail message. This may lead to… |
| CVE-2026-35541 | Media (4.2) | 0.31% | — | 3 abr 2026 | An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Incorrect password comparison in the password plugin could lead to type confusion that allows a password change without knowing the old password. |
| CVE-2026-35540 | Media (6.5) | 0.43% | — | 3 abr 2026 | An issue was discovered in Roundcube Webmail 1.6.0 before 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.