Roundcube vendor intelligence

Roundcube Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting Roundcube products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.

Total KEVs
12
Known exploited vulnerabilities affecting Roundcube products
In CISA KEV
11
Records also listed in the official catalog
Beyond CISA KEV
1
Additional exploited CVEs absent from CISA KEV
Sensor Observed
1
Roundcube KEV with sensor-observed exploitation activity

The catalog gap matters for Roundcube exposure

One of the twelve exploited Roundcube CVEs tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss 8% of this vendor portfolio.

92%
Covered by CISA
8%
Beyond CISA
3
Product families

Attested Roundcube CVEs

Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.

How exploitation is verified
CVE / description Product Confidence CISA KEV Added
CVE-2025-68461

Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document.

Webmail Confirmed In CISA 01 Jun 2026
CVE-2025-49113

Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is...

Webmail Confirmed In CISA 01 Jun 2026
CVE-2024-42009

A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a...

Roundcube Webmail Confirmed In CISA 01 Jun 2026
CVE-2013-1904

Absolute path traversal vulnerability in steps/mail/sendmail.inc in Roundcube Webmail before 0.7.3 and 0.8.x before 0.8.6 allows remote attackers...

Webmail High Beyond CISA 08 Feb 2014
CVE-2017-16651

Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's filesystem,...

Roundcube Webmail Confirmed In CISA 03 Nov 2021
CVE-2021-44026

Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.

Roundcube Webmail Confirmed In CISA 22 Jun 2023
CVE-2020-12641

rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setting...

Webmail Confirmed In CISA 22 Jun 2023
CVE-2020-35730

An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attacker can send a plain text...

Webmail Confirmed In CISA 22 Jun 2023
CVE-2023-5631

Stored XSS vulnerability in Roundcube

Roundcubemail Confirmed In CISA 26 Oct 2023
CVE-2023-43770

Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of...

Roundcube Webmail Confirmed In CISA 12 Feb 2024
CVE-2020-13965

An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is...

Webmail Confirmed In CISA 26 Jun 2024
CVE-2024-37383

Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.

Roundcube Webmail Confirmed In CISA 24 Oct 2024

Showing 12 of 12 Roundcube known exploited vulnerabilities.

Recurring weakness patterns

Neutralization, deserialization, and files or directories accessible to external parties account for eight mapped occurrences across this Roundcube KEV portfolio.

Browse all KEVs →

Early warning alerts

Get alerts on high-impact exploitation

Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.

Occasional high-impact alerts. Unsubscribe anytime. See our Privacy Policy.