Known Vulnerabilities for Webmail by Netwin
Listed below are 4 of the newest known vulnerabilities associated with "Webmail" by "Netwin".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-75010 json | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the modoboa driver of the password plugin could leak a Modoboa API... | Not Provided | 2026-08-17 | 2026-08-17 |
| CVE-2026-75007 json | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the LDAP search filter was subject to injection via unescaped %u/%... | Not Provided | 2026-08-17 | 2026-08-18 |
| CVE-2026-75006 json | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-m... | Not Provided | 2026-08-17 | 2026-08-17 |
| CVE-2026-75004 json | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper rule name quoting could lead to managesieve_disabled_acti... | Not Provided | 2026-08-17 | 2026-08-17 |
| CVE-2026-75003 json | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed url() in a FuncIRI attribute of an SVG image could eva... | Not Provided | 2026-08-17 | 2026-08-18 |
| CVE-2026-75002 json | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, mail search and LITERAL+ byte-count desynchronization could lead t... | Not Provided | 2026-08-17 | 2026-08-18 |
| CVE-2026-75000 json | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper HTML/CSS sanitization of the SVG animate "by" attribute m... | Not Provided | 2026-08-17 | 2026-08-18 |
| CVE-2026-74999 json | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the "Add to address book" action was subject to stored XSS. | Not Provided | 2026-08-17 | 2026-08-17 |
| CVE-2026-74998 json | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, responses from the CSS (Cascading Style Sheets) proxy were not val... | Not Provided | 2026-08-17 | 2026-08-17 |
| CVE-2026-74997 json | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the cmd_learn driver of the markasjunk plugin is subject to remote... | Not Provided | 2026-08-17 | 2026-08-17 |