Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Roundcube

First CVE: Dec 20, 2005Active for: 21 yearsTotal CVEs: 99
67.0
VTI Score
TOP TARGET

Roundcube is a widely deployed, browser-based webmail client embedded in mail hosting infrastructure and control panels across a large installed base, despite its narrow product portfolio. Vulnerabilities affecting the vendor skew toward serious outcomes and have an elevated tendency to be confirmed as exploited in the wild and cataloged by CISA, while public exploit code and proof-of-concept tooling frequently accompany disclosures. The recurring exposure centers on the webmail interface and clusters around input sanitization failures—particularly cross-site scripting and CSRF—alongside information-disclosure and path-traversal weaknesses that are characteristic of server-side web applications handling user-controlled input and file operations. Defenders should treat this vendor's advisories as high-priority for any internet-facing or hosted mail deployment and inventory instances that may be running unpatched versions; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
99
Total CVEs
More Total CVEs than 99% of tracked vendors
1.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 79% of tracked vendors
6.4
Avg CVSS Score
Higher Avg CVSS Score than 38% of tracked vendors
11.1%
In CISA KEV
Higher KEV Rate than 100% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Roundcube over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 20, 2005
20 years ago
Most Recent CVE
Jul 14, 2026
10 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (99 CVEs).

99 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-49113HIGH
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions
Jun 2, 20258.899YESYES
CVE-2024-42009CRITICAL
A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a crafted e-mail message t
Aug 5, 20249.397YESYES
CVE-2020-12641CRITICAL
rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setting for im_convert_path or im_identify_
May 4, 20209.896YESYES
CVE-2024-37383MEDIUM
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.
Jun 7, 20246.193YESYES
CVE-2020-13965MEDIUM
An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is among the allowed types for a pre
Jun 9, 20206.190YESNO
CVE-2023-5631MEDIUM
Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a crafted SVG document because of program/lib/Roundcube/rcube_
Oct 18, 20235.489YESNO
CVE-2017-16651HIGH
Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's filesystem, including configuration files, a
Nov 9, 20177.887YESYES
CVE-2021-44026CRITICAL
Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.
Nov 19, 20219.886YESNO
CVE-2023-43770MEDIUM
Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of program/lib/Roundcube/rcube_string_repla
Sep 22, 20236.185YESNO
CVE-2025-68461MEDIUM
Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document.
Dec 18, 20256.175YESNO
View all 99 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products99 CVEs
61%
23%
9%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (1.0%)
Network74 (74.7%)
Unknown24 (24.2%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low65 (65.7%)
High10 (10.1%)
Unknown24 (24.2%)
User Interaction
None36 (36.4%)
Unknown24 (24.2%)
Required39 (39.4%)
Privileges Required
Low17 (17.2%)
High0 (0.0%)
None58 (58.6%)
Unknown24 (24.2%)

Exploit Exposure

Signals from CVEs in this vendor scope (99 CVEs).

CISA KEV
11 CVEs
11.1% of CVEs· 100th percentile
Metasploit
2 CVEs
2.0% of CVEs· 97th percentile
Nuclei
3 CVEs
3.0% of CVEs· 95th percentile
ExploitDB
7 CVEs
7.1% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Roundcube.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Roundcube — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Roundcube's Products

View all 5 CNAs →

Top CWEs