Roundcube vendor intelligence
Roundcube Known Exploited Vulnerabilities
Track evidence-backed exploitation affecting Roundcube products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.
- Total KEVs
- 12
- Known exploited vulnerabilities affecting Roundcube products
- In CISA KEV
- 11
- Records also listed in the official catalog
- Beyond CISA KEV
- 1
- Additional exploited CVEs absent from CISA KEV
- Sensor Observed
- 1
- Roundcube KEV with sensor-observed exploitation activity
The catalog gap matters for Roundcube exposure
One of the twelve exploited Roundcube CVEs tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss 8% of this vendor portfolio.
- 92%
- Covered by CISA
- 8%
- Beyond CISA
- 3
- Product families
Attested Roundcube CVEs
Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.
How exploitation is verified| CVE / description | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2025-68461
Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document. |
Webmail | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2025-49113
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is... |
Webmail | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2024-42009
A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a... |
Roundcube Webmail | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2013-1904
Absolute path traversal vulnerability in steps/mail/sendmail.inc in Roundcube Webmail before 0.7.3 and 0.8.x before 0.8.6 allows remote attackers... |
Webmail | High | Beyond CISA | 08 Feb 2014 |
|
CVE-2017-16651
Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's filesystem,... |
Roundcube Webmail | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2021-44026
Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params. |
Roundcube Webmail | Confirmed | In CISA | 22 Jun 2023 |
|
CVE-2020-12641
rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setting... |
Webmail | Confirmed | In CISA | 22 Jun 2023 |
|
CVE-2020-35730
An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attacker can send a plain text... |
Webmail | Confirmed | In CISA | 22 Jun 2023 |
|
CVE-2023-5631
Stored XSS vulnerability in Roundcube |
Roundcubemail | Confirmed | In CISA | 26 Oct 2023 |
|
CVE-2023-43770
Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of... |
Roundcube Webmail | Confirmed | In CISA | 12 Feb 2024 |
|
CVE-2020-13965
An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is... |
Webmail | Confirmed | In CISA | 26 Jun 2024 |
|
CVE-2024-37383
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes. |
Roundcube Webmail | Confirmed | In CISA | 24 Oct 2024 |
No Roundcube CVEs match this search or filter.
Showing 12 of 12 Roundcube known exploited vulnerabilities.
Recurring weakness patterns
Neutralization, deserialization, and files or directories accessible to external parties account for eight mapped occurrences across this Roundcube KEV portfolio.
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CWE-502
Deserialization of Untrusted Data
CWE-552
Files or Directories Accessible to External Parties
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CWE-80
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Early warning alerts
Get alerts on high-impact exploitation
Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.