ZeroHour

Vulnerabilities

65 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-75003
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed url() in a FuncIRI attribute of an SVG image could evade the remote image blocking, which

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed url() in a FuncIRI attribute of an SVG image could evade the remote image blocking, which may lead to information disclosure or privilege escalation.

NVD description · AI analysis pending
9.8
group max
<1%
  • roundcube webmail
CVE-2026-54433
+4 in the same advisory: …62643 …62644 …62642 …62641
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafted plain-text email message.

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafted plain-text email message. The attacker-controlled JavaScript executes within the victim's authenticated session simply by opening or previewing the message (zero-click).

NVD description · AI analysis pending
10.0
group max
<1%
  • roundcube webmail
CVE-2026-35545
An issue was discovered in Roundcube Webmail before 1.5.15 and 1.6.15.

An issue was discovered in Roundcube Webmail before 1.5.15 and 1.6.15. The remote image blocking feature can be bypassed via SVG content in an e-mail message. This may lead to information disclosure or access-control bypass. This involves the animate element with attributeName=fill/filter/stroke.

NVD description · AI analysis pending
8.2
group max
<1%
  • roundcube webmail
CVE-2025-68461
+1 in the same advisory: …68460
Cross-Site Scripting via SVG animate Tag in Roundcube Webmail

Roundcube Webmail contains a cross-site scripting flaw (CWE-79) that arises when rendering SVG documents, because the SVG 'animate' element is not properly sanitized. An attacker can deliver a crafted SVG document, for example within an email, so that when the recipient views it in the Roundcube web interface, attacker-controlled script executes in the context of the victim's webmail session. Successful exploitation lets the attacker run arbitrary JavaScript in the victim's browser, enabling session hijacking, theft of cookies or credentials, and reading or manipulating the victim's mail and webmail settings. Any organization running Roundcube is potentially affected, including hosting providers, ISPs, universities, and enterprises, where it frequently serves as the default webmail client. CISA added the flaw to the KEV catalog on 2026-02-20, indicating confirmed in-the-wild exploitation, with a 26.8% EPSS probability of exploitation within 30 days (98th percentile); CVSS has not yet been scored and no public proof-of-concept is known.

Do: Upgrade Roundcube to the patched release identified in the vendor's security advisory, and for cPanel-managed servers apply the cPanel-shipped Roundcube update; do not defer patching given active exploitation. Until patched, apply vendor-recommended mitigations and hunt mail and web access logs for emails containing SVG content followed by anomalous webmail session activity. Federal agencies must apply the mitigations per vendor instructions or follow BOD 22-01 guidance per the CISA KEV listing.

6.1
group max
27% KEV
  • Roundcube Webmail
massplausibly millions of users across an estimated hundreds of thousands of deployments (tens of thousands of internet-exposed Roundcube servers visible in public…
CVE-2025-49113
Authenticated PHP Object Deserialization RCE in Roundcube Webmail

Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 contains a PHP object deserialization flaw (CWE-502) that allows remote code execution by authenticated users. The bug is in program/actions/settings/upload.php, where the _from URL parameter is not validated before deserialization, so any logged-in user can trigger it with a crafted URL to the settings upload action, with no user interaction required. Successful exploitation gives the attacker code execution on the web server with high confidentiality, integrity, and availability impact (CVSS 3.1 8.8). All deployments running affected versions are exposed, including Roundcube packages shipped with Debian Linux. The flaw reportedly existed for roughly a decade before disclosure, carries a 98.9% EPSS score (top percentile), and was added to CISA's KEV catalog on 2026-02-20, confirming exploitation in the wild.

Do: Upgrade to Roundcube 1.6.11 or 1.5.10 (or later); Debian administrators should install the fixed roundcube package via security updates. Hunt for compromise by reviewing web access logs for requests to the settings upload action with unusual or crafted _from parameters, and check the web server runtime for unexpected processes, files, or webshells. Federal agencies must apply mitigations per vendor instructions under BOD 22-01 or discontinue use of the product if mitigations are unavailable.

8.899% KEV PoC ×2
  • Roundcube Webmail all versions before 1.5.10, and 1.6.x before 1.6.11
  • Debian Linux (Roundcube Webmail package) Debian releases shipping affected Roundcube versions; fixes delivered via Debian security updates
masslikely tens of thousands of internet-exposed Roundcube instances serving millions of mailboxes
CVE-2024-57004
Stored XSS in Roundcube Webmail 1.6.9 via Malicious Email Attachment

Roundcube Webmail 1.6.9 contains a cross-site scripting flaw (CWE-80) in its attachment handling. An authenticated user can upload a malicious file as an email attachment, and the injected script executes when the SENT session is subsequently visited — for example, when the victim or another user views sent messages. Successful exploitation lets the attacker run arbitrary JavaScript in the victim's browser context, potentially hijacking the webmail session, stealing credentials or cookies, or reading mailbox content. Any organization or hosting provider serving Roundcube 1.6.9 webmail is exposed, which includes large numbers of end users at ISPs, universities, and cPanel-based hosting environments. A public proof-of-concept exists but the issue is not yet listed in CISA KEV; the high EPSS score (28.8%, 98th percentile) indicates an elevated likelihood of exploitation in the next 30 days.

Do: Upgrade Roundcube to the latest patched 1.6.x release, checking the vendor's security advisory for the fixed version, since exploitation requires only an authenticated upload and a victim viewing sent mail. As interim mitigation, restrict or sanitize attachment types and consider disabling or limiting access to the sent-message preview. Review webmail logs for suspicious attachment uploads and anomalous access to SENT sessions, and prioritize patching given the elevated EPSS score.

6.129% PoC
  • Roundcube Webmail 1.6.9 (as reported in the advisory; no broader version range specified)
massmillions of end users via tens of thousands of deployed instances
CVE-2024-42009
+1 in the same advisory: …42008
Cross-Site Scripting in Roundcube Webmail Lets Attackers Steal Emails

CVE-2024-42009 is a cross-site scripting (CWE-79) vulnerability in Roundcube Webmail versions through 1.5.7 and 1.6.x through 1.6.7, caused by a desanitization issue in message_body() in program/actions/mail/show.php. An attacker sends a specially crafted email, and when the victim opens it in the Roundcube interface, injected script runs in the context of the victim's webmail session (no privileges are required, but user interaction is needed, per the CVSS UI:R vector). Successful exploitation lets the attacker steal the victim's emails and send messages as the victim, and related reporting notes that, chained with the companion flaw CVE-2024-42008, attackers can compromise email accounts and passwords. Any organization or provider self-hosting an affected Roundcube version is exposed, including universities, hosting providers, enterprises, and government mail systems. Exploitation is confirmed in the wild: CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2025-06-09, EPSS is 82.9% (100th percentile), and recent headlines describe suspected China-aligned espionage activity using Roundcube exploit chains against universities.

Do: Upgrade Roundcube to a point release newer than 1.6.7 on the 1.6.x line or newer than 1.5.7 on the 1.5.x line (the latest vendor release of each branch), per vendor instructions; organizations under BOD 22-01 must apply the required mitigations by the KEV due date or discontinue use. Also patch the companion issue CVE-2024-42008 to prevent chained account compromise. Review webmail access logs for suspicious requests to the mail show handler, check sent-mail folders for messages sent unexpectedly as users, and rotate sessions/credentials for potentially targeted accounts.

9.383% KEV
  • Roundcube Webmail all versions through 1.5.7 and all 1.6.x versions through 1.6.7
massroughly millions of users across tens of thousands of self-hosted instances (public scans show tens of thousands of internet-exposed Roundcube servers)
CVE-2024-37383
+2 in the same advisory: …37385 …37384
Cross-Site Scripting in Roundcube Webmail via SVG animate attributes

CVE-2024-37383 is a cross-site scripting vulnerability (CWE-79) in Roundcube Webmail caused by insufficient handling of SVG 'animate' attributes when HTML email content is rendered. An attacker triggers it by sending a crafted HTML email containing a malicious SVG animate element; when the recipient views the message in Roundcube, attacker-controlled JavaScript executes in the context of the victim's webmail session. Successful exploitation allows theft of session cookies and credentials, access to mailbox contents, sending mail as the victim, or redirection to phishing pages, and has been used in campaigns that steal credentials and email. All Roundcube Webmail deployments before 1.5.7 and 1.6.x before 1.6.7 are affected, including Roundcube packages shipped with Debian; because the attack requires only viewing a malicious email, any exposed webmail user is a potential victim. The flaw is under active exploitation: unknown threat actors have used it in phishing campaigns, it carries an EPSS of 73.3%, and CISA added it to the Known Exploited Vulnerabilities catalog on 2024-10-24.

Do: Upgrade Roundcube to version 1.5.7 or 1.6.7 (or later) immediately; Debian users should install the updated roundcube package from their repository. Organizations subject to CISA BOD 22-01 must apply vendor mitigations or discontinue use per the KEV entry. Review webmail logs for phishing emails containing SVG animate elements and investigate for credential theft or anomalous mailbox activity.

6.1
group max
73% KEV
  • Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 (i.e., 1.6.0 through 1.6.6 and earlier releases)
  • Debian Linux (Roundcube webmail package)
masslikely millions of webmail users across hundreds of thousands of deployed instances, with tens of thousands of instances internet-exposed
CVE-2023-47272
Roundcube 1.5.x before 1.5.6 and 1.6.x before 1.6.5 allows XSS via a Content-Type or Content-Disposition header (used for attachment preview or download).

Roundcube 1.5.x before 1.5.6 and 1.6.x before 1.6.5 allows XSS via a Content-Type or Content-Disposition header (used for attachment preview or download).

NVD description · AI analysis pending
6.1<1%
  • roundcube webmail
  • roundcube fedora
  • roundcube debian linux
CVE-2023-5631
Stored XSS in Roundcube Webmail exploited in the wild (CVE-2023-5631)

CVE-2023-5631 is a stored cross-site scripting (XSS) flaw in Roundcube Webmail caused by insufficient sanitization of SVG content embedded in HTML email by program/lib/Roundcube/rcube_washtml.php. A remote attacker triggers it by sending a crafted HTML email containing a malicious SVG document; when the recipient views the message, arbitrary JavaScript is loaded in their browser session. This lets the attacker act as the victim within the webmail session — for example reading mail or capturing session data — and it has been used in targeted espionage rather than commodity attacks. Anyone running Roundcube before 1.4.15, 1.5.x before 1.5.5, or 1.6.x before 1.6.4 is affected, including Roundcube packages shipped by Debian and Fedora. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2023-10-26, the Winter Vivern espionage group is reported to have exploited it as a zero-day against government entities, and EPSS puts the 30-day exploitation probability at ~76% (99th percentile).

Do: Upgrade to Roundcube 1.6.4, or 1.5.5 on the 1.5.x branch and 1.4.15 on the 1.4.x branch; apply the corresponding patched roundcube packages for Debian or Fedora. Per the CISA KEV required action, apply vendor mitigations or discontinue use if patching is unavailable. Hunt for compromise by reviewing webmail logs and stored messages for crafted SVG/HTML emails sent around the exploitation window, and review sessions for signs of hijacking.

5.476% KEV PoC
  • Roundcube Webmail All versions before 1.4.15; 1.5.x before 1.5.5; 1.6.x before 1.6.4
  • Debian Linux (roundcube webmail package) Debian releases shipping Roundcube prior to 1.4.15 / 1.5.5 / 1.6.4
  • Fedora (roundcube webmail package) Fedora releases shipping Roundcube prior to 1.4.15 / 1.5.5 / 1.6.4
largetens of thousands of internet-exposed Roundcube servers; plausibly 100k+ end users, unknown precisely
CVE-2023-43770
Persistent Cross-Site Scripting in Roundcube Webmail (Exploited in the Wild)

Roundcube Webmail versions before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 contain a persistent cross-site scripting (XSS) flaw (CWE-79) caused by how program/lib/Roundcube/rcube_string_replacer.php converts plain text into clickable links. An attacker sends a text/plain email containing crafted links; when the recipient views the message, the crafted link text is turned into HTML that runs attacker-controlled script, which persists and executes in the victim's webmail session. Successful exploitation lets the attacker execute JavaScript with the victim's session, enabling mailbox access, theft of session credentials, and actions performed as the user (CVSS 6.1, scope-changed with limited confidentiality and integrity impact). Anyone running an affected Roundcube instance is exposed, including the roundcube package shipped with Debian Linux. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-02-12, and EPSS assigns a 58.5% probability of exploitation within 30 days (99th percentile).

Do: Upgrade Roundcube to 1.4.14, 1.5.4, or 1.6.3 (or later, per branch), or install the updated roundcube package on Debian. Because the bug is in CISA's KEV catalog, U.S. federal agencies must apply the vendor fix by the catalog due date, and other defenders should prioritize patching internet-facing webmail servers. Review webmail access logs for suspicious message views or account activity, and consider forcing session re-authentication for accounts that opened crafted plain-text messages.

6.158% KEV
  • Roundcube Webmail before 1.4.14; 1.5.x before 1.5.4; 1.6.x before 1.6.3
  • Debian Linux (roundcube package)
massplausibly millions of users across tens of thousands of internet-exposed Roundcube instances (estimate)
CVE-2021-46144
Roundcube before 1.4.13 and 1.5.x before 1.5.2 allows XSS via an HTML e-mail message with crafted Cascading Style Sheets (CSS) token sequences.

Roundcube before 1.4.13 and 1.5.x before 1.5.2 allows XSS via an HTML e-mail message with crafted Cascading Style Sheets (CSS) token sequences.

NVD description · AI analysis pending
6.11%
  • roundcube roundcube
  • roundcube debian linux
CVE-2021-44026
SQL Injection in Roundcube Webmail via Search Parameters

Roundcube Webmail contains a SQL injection flaw (CWE-89) in which attacker-controlled 'search' or 'search_params' input is incorporated into database queries without sufficient sanitization. An attacker with access to the webmail search functionality (typically an authenticated mailbox user) can submit crafted parameters to execute arbitrary SQL against the Roundcube backend database, potentially reading or modifying stored mail account data. Any organization running Roundcube is affected, including self-hosted mail servers and customers of hosting providers that ship Roundcube as their bundled webmail client. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2023-06-22, indicating exploitation in the wild, and EPSS assigns a 41.9% probability of exploitation within 30 days (99th percentile). No public proof-of-concept is known, and CISA lists ransomware use as unknown.

Do: Apply vendor updates per Roundcube's instructions by upgrading to the latest patched, supported release, prioritizing internet-facing webmail servers; federal agencies must remediate per the CISA KEV requirement. If Roundcube is managed by a hosting provider (e.g., via cPanel), coordinate patching with them. In the interim, restrict webmail exposure and review database and web logs for anomalous search-related queries that may indicate exploitation.

9.842% KEV
  • Roundcube Webmail
massmillions of users across tens of thousands of exposed Roundcube deployments (estimated)
CVE-2021-44025
Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to XSS in handling an attachment's filename extension when displaying a MIME type warning message.

Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to XSS in handling an attachment's filename extension when displaying a MIME type warning message.

NVD description · AI analysis pending
6.11%
  • roundcube webmail
  • roundcube fedora
  • roundcube debian linux
CVE-2020-18670
+1 in the same advisory: …18671
Cross Site Scripting (XSS) vulneraibility in Roundcube mail .4.4 via database host and user in /installer/test.php.

Cross Site Scripting (XSS) vulneraibility in Roundcube mail .4.4 via database host and user in /installer/test.php.

NVD description · AI analysis pending
5.4<1% PoC
  • roundcube webmail
CVE-2021-26925
Roundcube before 1.4.11 allows XSS via crafted Cascading Style Sheets (CSS) token sequences during HTML email rendering.

Roundcube before 1.4.11 allows XSS via crafted Cascading Style Sheets (CSS) token sequences during HTML email rendering.

NVD description · AI analysis pending
5.41%
  • roundcube webmail
  • roundcube fedora
CVE-2020-35730
Cross-Site Scripting in Roundcube Webmail Plain-Text Email Link Handling

Roundcube Webmail contains a cross-site scripting (XSS) flaw (CWE-79) in the link-reference handling of rcube_string_replacer.php, where the linkref_addindex function mishandles JavaScript embedded in a link element of a plain-text email. An attacker triggers the flaw simply by sending a crafted plain-text message to a victim; when the message is processed/displayed in the Roundcube interface, the embedded script executes in the context of the victim's webmail session. Successful exploitation can lead to session hijacking, theft of webmail cookies or credentials, and arbitrary actions in the victim's mailbox. Any deployment of Roundcube Webmail is affected, which includes self-hosted instances and webmail offered by hosting providers, ISPs, and universities. Although no public proof-of-concept is known, CISA added this vulnerability to the Known Exploited Vulnerabilities catalog on 2023-06-22, confirming exploitation in the wild; ransomware association is unknown, and no CVSS score is yet available, though EPSS puts 30-day exploitation probability at 32.7% (98th percentile).

Do: Apply the vendor's updated Roundcube release per CISA's required action (updates per vendor instructions); since no specific fixed versions appear in this data, install the latest patched release of your deployed 1.x branch and verify with the vendor advisory. Check webmail servers for processing of plain-text messages with link-reference elements and review logs for anomalous webmail sessions; treat KEV-listed status as evidence of active exploitation and prioritize internet-exposed Roundcube instances.

6.133% KEV
  • Roundcube Webmail
masslikely >1M users across tens of thousands of exposed instances (Roundcube is bundled as webmail in cPanel/Plesk and by many ISPs)
CVE-2020-16145
Roundcube Webmail before 1.3.15 and 1.4.8 allows stored XSS in HTML messages during message display via a crafted SVG document.

Roundcube Webmail before 1.3.15 and 1.4.8 allows stored XSS in HTML messages during message display via a crafted SVG document. This issue has been fixed in 1.4.8 and 1.3.15.

NVD description · AI analysis pending
6.12%
  • roundcube webmail
  • roundcube fedora
CVE-2020-15562
An issue was discovered in Roundcube Webmail before 1.2.11, 1.3.x before 1.3.14, and 1.4.x before 1.4.7.

An issue was discovered in Roundcube Webmail before 1.2.11, 1.3.x before 1.3.14, and 1.4.x before 1.4.7. It allows XSS via a crafted HTML e-mail message, as demonstrated by a JavaScript payload in the xmlns (aka XML namespace) attribute of a HEAD element when an SVG element exists.

NVD description · AI analysis pending
6.12%
  • roundcube webmail
  • roundcube debian linux
CVE-2020-13965
+1 in the same advisory: …13964
XSS via Malicious XML Attachment in Roundcube Webmail

Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5 is vulnerable to cross-site scripting via malicious XML attachments, because text/xml is among the MIME types the client renders in the attachment preview, allowing embedded markup or script to execute in the victim's browser. An attacker triggers the flaw by emailing a crafted XML attachment and persuading a user to preview it. Successful exploitation lets the attacker run arbitrary JavaScript in the victim's webmail session, potentially hijacking the session, reading or manipulating mail, or acting as the user. Any Roundcube deployment running an affected version is exposed, including the Roundcube packages shipped in Debian and Fedora, though the share of installs still unpatched in 2024 is not documented in the available data. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2024-06-26, confirming exploitation in the wild, and a public proof-of-concept is available with EPSS at roughly 77% probability of exploitation within 30 days.

Do: Upgrade Roundcube to 1.3.12 or later on the 1.3 branch, or 1.4.5 or later on the 1.4 branch. If immediate patching is not possible, apply vendor mitigations — such as removing text/xml from the MIME types permitted for attachment preview — or discontinue use of the product per CISA's required action. Audit mail servers and hosting panels for Roundcube versions and monitor for suspicious activity around XML attachment previews.

6.177% KEV PoC
  • Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5
  • Debian Linux (Roundcube package) packages shipping Roundcube before 1.3.12 or 1.4.x before 1.4.5 (exact affected Debian releases not specified in source data)
  • fedoraproject Fedora (Roundcube package) packages shipping Roundcube before 1.3.12 or 1.4.x before 1.4.5 (exact affected Fedora releases not specified in source data)
massmillions of users across hundreds of thousands of deployments; count of currently unpatched instances unknown
CVE-2020-12641
Command Injection RCE in Roundcube Webmail (CVE-2020-12641)

Roundcube Webmail versions before 1.4.4 contain an OS command injection flaw (CWE-78) in rcube_image.php: shell metacharacters in the im_convert_path or im_identify_path configuration settings are not escaped before the configured ImageMagick binaries are executed. When image processing is triggered, an attacker who can control those configuration values can append arbitrary shell commands that run with the privileges of the web server user, yielding full remote code execution on the mail server. Successful exploitation can expose stored email, mail credentials, and the underlying host; the flaw is scored 9.8 (critical), with no privileges or user interaction required per the CVSS vector. Any self-hosted Roundcube deployment older than 1.4.4 is affected, including Roundcube packages shipped by openSUSE Leap and openSUSE Backports for SUSE Linux Enterprise. Exploitation is confirmed in the wild: CISA added it to the KEV catalog on 2023-06-22, EPSS puts the 30-day exploitation probability at ~84%, and headlines note APT28-linked activity targeting government Roundcube servers, including Ukrainian entities.

Do: Upgrade Roundcube to 1.4.4 or later, or apply the vendor-patched openSUSE Leap / SLE backport packages, as required by the CISA KEV listing (added 2023-06-22). After patching, verify that im_convert_path and im_identify_path settings contain no unescaped metacharacters and review web server logs for injected command activity; given APT28's targeting of government Roundcube servers, prioritize public-sector mail infrastructure for patching and threat hunting.

9.884% KEV PoC
  • roundcube webmail all versions before 1.4.4
  • opensuse leap packages shipping Roundcube before 1.4.4 (fixed via openSUSE updates)
  • opensuse backports sle packages shipping Roundcube before 1.4.4 (fixed via openSUSE updates)
masstens of thousands of internet-exposed Roundcube instances; millions of end users via bundled/self-hosted deployments (estimate)
CVE-2020-12640
+1 in the same advisory: …12626
Roundcube Webmail before 1.4.4 allows attackers to include local files and execute code via directory traversal in a plugin name to rcube_plugin_api.php.

Roundcube Webmail before 1.4.4 allows attackers to include local files and execute code via directory traversal in a plugin name to rcube_plugin_api.php.

NVD description · AI analysis pending
9.8
group max
7% PoC
  • roundcube webmail
  • roundcube backports sle
  • roundcube leap