Webmail
Vendor:
First CVE: Dec 20, 2005 · Active for 20 years
96
Total CVEs
More Total CVEs than 99% of tracked products
4.8
Avg CVEs / Year
Higher CVE frequency than 87% of tracked products
6.4
Avg CVSS
Higher Avg CVSS than 27% of tracked products
11.5%
KEV Rate
Higher KEV Rate than 97% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Webmail over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 20, 2005
20 years ago
Most Recent CVE
Jul 14, 2026
10 days ago
CVE Severity & Scoring
Webmail96 CVEs
60%
23%
9%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (1.0%)
Network71 (74.0%)
Unknown24 (25.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low63 (65.6%)
High9 (9.4%)
Unknown24 (25.0%)
User Interaction
None34 (35.4%)
Unknown24 (25.0%)
Required38 (39.6%)
Privileges Required
Low15 (15.6%)
High0 (0.0%)
None57 (59.4%)
Unknown24 (25.0%)
Top CVEs
Signals from CVEs in this product scope (96 CVEs).
96 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-49113HIGH Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions | Jun 2, 2025 | 8.8 | 99 | YES | YES |
CVE-2024-42009CRITICAL A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a crafted e-mail message t | Aug 5, 2024 | 9.3 | 97 | YES | YES |
CVE-2020-12641CRITICAL rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setting for im_convert_path or im_identify_ | May 4, 2020 | 9.8 | 96 | YES | YES |
CVE-2024-37383MEDIUM Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes. | Jun 7, 2024 | 6.1 | 93 | YES | YES |
CVE-2020-13965MEDIUM An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is among the allowed types for a pre | Jun 9, 2020 | 6.1 | 90 | YES | NO |
CVE-2023-5631MEDIUM Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a crafted SVG document because of program/lib/Roundcube/rcube_ | Oct 18, 2023 | 5.4 | 89 | YES | NO |
CVE-2017-16651HIGH Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's filesystem, including configuration files, a | Nov 9, 2017 | 7.8 | 87 | YES | YES |
CVE-2021-44026CRITICAL Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params. | Nov 19, 2021 | 9.8 | 86 | YES | NO |
CVE-2023-43770MEDIUM Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of program/lib/Roundcube/rcube_string_repla | Sep 22, 2023 | 6.1 | 85 | YES | NO |
CVE-2025-68461MEDIUM Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document. | Dec 18, 2025 | 6.1 | 75 | YES | NO |
Exploit Exposure
Signals from CVEs in this product scope (96 CVEs).
CISA KEV
11 CVEs
11.5% of CVEs· 97th percentile
Metasploit
2 CVEs
2.1% of CVEs· 96th percentile
Nuclei
3 CVEs
3.1% of CVEs· 96th percentile
ExploitDB
6 CVEs
6.2% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (96 CVEs).
Media Mentions
Signals from CVEs in this product scope (96 CVEs).
Top CNAs Publishing CVEs For Webmail
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.6.9 | 1 | 6.1 | 28.8% | 0 | 0 |
| 1.4.4 | 1 | 5.4 | 0.9% | 0 | 0 |
| 1.3.2 | 1 | 7.8 | 36.9% | 1 | 1 |
| 1.3.1 | 1 | 7.8 | 36.9% | 1 | 1 |
| 1.3.0 | 1 | 7.8 | 36.9% | 1 | 1 |
| 1.2.6 | 1 | 7.8 | 36.9% | 1 | 1 |
| 1.2.5 | 1 | 7.8 | 36.9% | 1 | 1 |
| 1.2.4 | 1 | 7.8 | 36.9% | 1 | 1 |
| 1.2.3 | 2 | 7.0 | 19.1% | 1 | 1 |
| 1.2.2 | 3 | 7.1 | 14.6% | 1 | 1 |
| 1.2.1 | 3 | 7.1 | 14.6% | 1 | 1 |
| 1.2.0 | 3 | 7.1 | 14.6% | 1 | 1 |
| 1.2 | 1 | 6.1 | 1.4% | 0 | 0 |
| 1.1.4 | 2 | 6.1 | 2.6% | 0 | 0 |
| 1.1.2 | 1 | 3.5 | 1.5% | 0 | 0 |
| 1.1.1 | 2 | 4.8 | 1.4% | 0 | 0 |
| 1.1.0 | 2 | 4.8 | 1.4% | 0 | 0 |
| 1.1 | 5 | 6.5 | 2.9% | 0 | 0 |
| 1.0 | 1 | 3.5 | 1.1% | 0 | 0 |
| 0.9.4 | 1 | 7.5 | 2.9% | 0 | 0 |