Known Vulnerabilities for Roundcube Webmail by Roundcube
Listed below are 8 of the newest known vulnerabilities associated with "Roundcube Webmail" by "Roundcube".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-35545 | An issue was discovered in Roundcube Webmail before 1.5.15 and 1.6.15. The remote image blocking feature can be bypassed via ... | Not Provided | 2026-04-03 | 2026-04-03 |
| CVE-2026-35544 | An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization... | Not Provided | 2026-04-03 | 2026-04-03 |
| CVE-2026-35543 | An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via ... | Not Provided | 2026-04-03 | 2026-04-03 |
| CVE-2026-35542 | An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via ... | Not Provided | 2026-04-03 | 2026-04-03 |
| CVE-2026-35541 | An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Incorrect password comparison in the password plugin c... | Not Provided | 2026-04-03 | 2026-04-03 |
| CVE-2026-35540 | An issue was discovered in Roundcube Webmail 1.6.0 before 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in H... | Not Provided | 2026-04-03 | 2026-04-03 |
| CVE-2026-35539 | An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. XSS exists because of insufficient HTML attachment san... | Not Provided | 2026-04-03 | 2026-04-03 |
| CVE-2026-35538 | An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsanitized IMAP SEARCH command arguments could lead t... | Not Provided | 2026-04-03 | 2026-04-03 |
| CVE-2026-35537 | An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsafe deserialization in the redis/memcache session h... | Not Provided | 2026-04-03 | 2026-04-03 |
| CVE-2017-8114 | Roundcube Webmail allows arbitrary password resets by authenticated users. This affects versions before 1.0.11, 1.1.x before ... | 8.8 - HIGH | 2017-04-29 | 2022-09-27 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Roundcube | Roundcube Webmail | 1.2.3 | All | All | All |
| Application | Roundcube | Roundcube Webmail | 1.2.2 | All | All | All |
| Application | Roundcube | Roundcube Webmail | 1.2.1 | All | All | All |
| Application | Roundcube | Roundcube Webmail | 1.2.0 | All | All | All |
| Application | Roundcube | Roundcube Webmail | 1.1.7 | All | All | All |
| Application | Roundcube | Roundcube Webmail | 1.1.4 | All | All | All |
| Application | Roundcube | Roundcube Webmail | 1.1 | All | All | All |
| Application | Roundcube | Roundcube Webmail | 1.1 | beta | All | All |
| Application | Roundcube | Roundcube Webmail | 1.1 | rc | All | All |
| Application | Roundcube | Roundcube Webmail | 1.0.8 | All | All | All |