Webmail

Vendor:

First CVE: Dec 20, 2005 · Active for 20 years

96
Total CVEs
More Total CVEs than 99% of tracked products
4.8
Avg CVEs / Year
Higher CVE frequency than 87% of tracked products
6.4
Avg CVSS
Higher Avg CVSS than 27% of tracked products
11.5%
KEV Rate
Higher KEV Rate than 97% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Webmail over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 20, 2005
20 years ago
Most Recent CVE
Jul 14, 2026
10 days ago

CVE Severity & Scoring

Webmail96 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local1 (1.0%)
Network71 (74.0%)
Unknown24 (25.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low63 (65.6%)
High9 (9.4%)
Unknown24 (25.0%)
User Interaction
None34 (35.4%)
Unknown24 (25.0%)
Required38 (39.6%)
Privileges Required
Low15 (15.6%)
High0 (0.0%)
None57 (59.4%)
Unknown24 (25.0%)

Top CVEs

Signals from CVEs in this product scope (96 CVEs).

96 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions
Jun 2, 20258.899YESYES
A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a crafted e-mail message t
Aug 5, 20249.397YESYES
rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setting for im_convert_path or im_identify_
May 4, 20209.896YESYES
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.
Jun 7, 20246.193YESYES
An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is among the allowed types for a pre
Jun 9, 20206.190YESNO
Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a crafted SVG document because of program/lib/Roundcube/rcube_
Oct 18, 20235.489YESNO
Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's filesystem, including configuration files, a
Nov 9, 20177.887YESYES
Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.
Nov 19, 20219.886YESNO
Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of program/lib/Roundcube/rcube_string_repla
Sep 22, 20236.185YESNO
Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document.
Dec 18, 20256.175YESNO

Exploit Exposure

Signals from CVEs in this product scope (96 CVEs).

CISA KEV
11 CVEs
11.5% of CVEs· 97th percentile
Metasploit
2 CVEs
2.1% of CVEs· 96th percentile
Nuclei
3 CVEs
3.1% of CVEs· 96th percentile
ExploitDB
6 CVEs
6.2% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (96 CVEs).

Media Mentions

Signals from CVEs in this product scope (96 CVEs).

Top CNAs Publishing CVEs For Webmail

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
1.6.916.128.8%00
1.4.415.40.9%00
1.3.217.836.9%11
1.3.117.836.9%11
1.3.017.836.9%11
1.2.617.836.9%11
1.2.517.836.9%11
1.2.417.836.9%11
1.2.327.019.1%11
1.2.237.114.6%11
1.2.137.114.6%11
1.2.037.114.6%11
1.216.11.4%00
1.1.426.12.6%00
1.1.213.51.5%00
1.1.124.81.4%00
1.1.024.81.4%00
1.156.52.9%00
1.013.51.1%00
0.9.417.52.9%00