📦 Webmail

by Roundcube

🔍 What is Webmail?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-49113

CRITICAL CVSS 9.9 Jun 2, 2025

CVE-2025-49113 is a critical remote code execution vulnerability in Roundcube Webmail affecting authenticated users. It allows attackers to execute arbitrary PHP code on the server by exploiting impro...

CVE-2024-42008

CRITICAL CVSS 9.3 Aug 5, 2024

A Cross-Site Scripting vulnerability in Roundcube webmail allows attackers to steal and send victims' emails via malicious email attachments with dangerous Content-Type headers. This affects Roundcube...

CVE-2024-37385

CRITICAL CVSS 9.8 Jun 7, 2024

This vulnerability allows remote command injection in Roundcube Webmail on Windows systems through the im_convert_path and im_identify_path parameters. Attackers can execute arbitrary commands on the ...

CVE-2021-44026

CRITICAL CVSS 9.8 Nov 19, 2021

This SQL injection vulnerability in Roundcube webmail allows attackers to execute arbitrary SQL commands via search or search_params parameters. It affects all Roundcube installations before version 1...

CVE-2025-68461

HIGH CVSS 7.2 Dec 18, 2025

This CVE describes a Cross-Site Scripting (XSS) vulnerability in Roundcube Webmail that allows attackers to inject malicious scripts via the animate tag in SVG documents. When exploited, this can lead...

CVE-2025-68460

HIGH CVSS 7.2 Dec 18, 2025

Roundcube Webmail contains an information disclosure vulnerability in its HTML style sanitizer that could allow attackers to extract sensitive data from email content. This affects all Roundcube insta...

CVE-2024-57004

MEDIUM CVSS 6.1 Feb 3, 2025

This Cross-Site Scripting (XSS) vulnerability in Roundcube Webmail allows authenticated users to upload malicious files as email attachments. When recipients view these emails in their SENT folder, th...

CVE-2024-37383

MEDIUM CVSS 6.1 Jun 7, 2024

This Cross-Site Scripting (XSS) vulnerability in Roundcube Webmail allows attackers to inject malicious scripts via SVG animate attributes. When exploited, it enables session hijacking, credential the...