Known Vulnerabilities for products from Roundcube

Listed below are 20 of the newest known vulnerabilities associated with the vendor "Roundcube".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2026-35545 Not Provided 2026-04-03 2026-04-03
CVE-2026-35544 Not Provided 2026-04-03 2026-04-03
CVE-2026-35543 Not Provided 2026-04-03 2026-04-03
CVE-2026-35542 Not Provided 2026-04-03 2026-04-03
CVE-2026-35541 Not Provided 2026-04-03 2026-04-03
CVE-2026-35540 Not Provided 2026-04-03 2026-04-03
CVE-2026-35539 Not Provided 2026-04-03 2026-04-03
CVE-2026-35538 Not Provided 2026-04-03 2026-04-03
CVE-2026-35537 Not Provided 2026-04-03 2026-04-03
CVE-2021-26925 Roundcube before 1.4.11 allows XSS via crafted Cascading Style Sheets (CSS) token sequences during HTML email rendering. 5.4 - MEDIUM 2021-02-09 2023-11-07
CVE-2020-35730 An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attacker ca... 6.1 - MEDIUM 2020-12-28 2023-11-07
CVE-2020-18671 Cross Site Scripting (XSS) vulnerability in Roundcube Mail <=1.4.4 via smtp config in /installer/test.php. 5.4 - MEDIUM 2021-06-24 2022-03-10
CVE-2020-18670 Cross Site Scripting (XSS) vulneraibility in Roundcube mail .4.4 via database host and user in /installer/test.php. 5.4 - MEDIUM 2021-06-24 2022-03-10
CVE-2020-16145 Roundcube Webmail before 1.3.15 and 1.4.8 allows stored XSS in HTML messages during message display via a crafted SVG documen... 6.1 - MEDIUM 2020-08-12 2023-11-07
CVE-2020-15562 An issue was discovered in Roundcube Webmail before 1.2.11, 1.3.x before 1.3.14, and 1.4.x before 1.4.7. It allows XSS via a ... 6.1 - MEDIUM 2020-07-06 2023-01-20
CVE-2020-13965 An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachmen... 6.1 - MEDIUM 2020-06-09 2023-11-07
CVE-2020-13964 An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. include/rcmail_output_html.php allows XSS ... 6.1 - MEDIUM 2020-06-09 2023-11-07
CVE-2020-12641 rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a co... 9.8 - CRITICAL 2020-05-04 2022-04-29
CVE-2020-12640 Roundcube Webmail before 1.4.4 allows attackers to include local files and execute code via directory traversal in a plugin n... 9.8 - CRITICAL 2020-05-04 2022-09-02
CVE-2020-12626 An issue was discovered in Roundcube Webmail before 1.4.4. A CSRF attack can cause an authenticated user to be logged out bec... 6.5 - MEDIUM 2020-05-04 2022-09-02

Known software with vulnerabilities from Roundcube

Type Vendor Product Version
ApplicationRoundcubeRoundcube0.1
ApplicationRoundcubeRoundcube Webmail1.0.8
ApplicationRoundcubeWebmail0.1