Roundcube is a widely deployed, browser-based webmail client embedded in mail hosting infrastructure and control panels across a large installed base, despite its narrow product portfolio. Vulnerabilities affecting the vendor skew toward serious outcomes and have an elevated tendency to be confirmed as exploited in the wild and cataloged by CISA, while public exploit code and proof-of-concept tooling frequently accompany disclosures. The recurring exposure centers on the webmail interface and clusters around input sanitization failures—particularly cross-site scripting and CSRF—alongside information-disclosure and path-traversal weaknesses that are characteristic of server-side web applications handling user-controlled input and file operations. Defenders should treat this vendor's advisories as high-priority for any internet-facing or hosted mail deployment and inventory instances that may be running unpatched versions; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Roundcube over time
Signals from CVEs in this vendor scope (99 CVEs).
99 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-49113HIGH Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions | Jun 2, 2025 | 8.8 | 99 | YES | YES |
CVE-2024-42009CRITICAL A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a crafted e-mail message t | Aug 5, 2024 | 9.3 | 97 | YES | YES |
CVE-2020-12641CRITICAL rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setting for im_convert_path or im_identify_ | May 4, 2020 | 9.8 | 96 | YES | YES |
CVE-2024-37383MEDIUM Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes. | Jun 7, 2024 | 6.1 | 93 | YES | YES |
CVE-2020-13965MEDIUM An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is among the allowed types for a pre | Jun 9, 2020 | 6.1 | 90 | YES | NO |
CVE-2023-5631MEDIUM Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a crafted SVG document because of program/lib/Roundcube/rcube_ | Oct 18, 2023 | 5.4 | 89 | YES | NO |
CVE-2017-16651HIGH Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's filesystem, including configuration files, a | Nov 9, 2017 | 7.8 | 87 | YES | YES |
CVE-2021-44026CRITICAL Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params. | Nov 19, 2021 | 9.8 | 86 | YES | NO |
CVE-2023-43770MEDIUM Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of program/lib/Roundcube/rcube_string_repla | Sep 22, 2023 | 6.1 | 85 | YES | NO |
CVE-2025-68461MEDIUM Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document. | Dec 18, 2025 | 6.1 | 75 | YES | NO |
Signals from CVEs in this vendor scope (99 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Roundcube.
Media articles that mention a CVE ID that affects a product developed by Roundcube — matched by CVE ID, not by vendor name.