Exposición de RoundCube

Webmail
119
score de exposición
1434
sitios usan
3
en explotación
1
críticos
Análisis Vexday

RoundCube apresenta uma taxa de exploração ativa expressivamente acima da média do catálogo CISA KEV, com 3 de suas 23 CVEs catalogadas confirmadas em uso por agentes maliciosos — proporção 29 vezes superior à média geral, o que indica histórico concreto de aproveitamento oportunista dessa superfície de ataque. O volume recente é igualmente preocupante: 17 vulnerabilidades surgiram nos últimos 90 dias, sugerindo aumento relevante na atenção de pesquisadores e atacantes à plataforma. A CVE mais crítica atualmente ativa, CVE-2025-49113, registra EPSS de 0,89, valor próximo ao teto da escala, sinalizando altíssima probabilidade de exploração iminente ou em curso. Equipes responsáveis por instâncias RoundCube devem tratar a aplicação de patches como prioridade imediata, com atenção especial às falhas classificadas sob CWE-669, padrão de fraqueza dominante no conjunto de vulnerabilidades desta tecnologia.

CVEs

39 resultados
CVE-2026-35540MEDIUMAn issue was discovered in Roundcube Webmail 1.6.0 before 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messEPSS 0.4%CVE-2026-48845MEDIUMIn Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16 and 1.7.x before 1.7.1, remote image blocking was not honored for URLs pointing to locaEPSS 0.4%CVE-2026-35544MEDIUMAn issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mailEPSS 0.4%CVE-2026-75007MEDIUMIn Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the LDAP search filter was subject to injection via unescaped %u/%fu/%d substitutEPSS 0.4%CVE-2026-75000MEDIUMIn Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper HTML/CSS sanitization of the SVG animate "by" attribute may lead to remoEPSS 0.3%CVE-2026-35538LOWAn issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsanitized IMAP SEARCH command arguments could lead to IMAP injectioEPSS 0.3%CVE-2026-74998HIGHIn Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, responses from the CSS (Cascading Style Sheets) proxy were not validated, which mEPSS 0.3%CVE-2026-54433HIGHIn Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafted plain-text email messageEPSS 0.3%CVE-2026-26079MEDIUMRoundcube Webmail before 1.5.13 and 1.6 before 1.6.13 allows Cascading Style Sheets (CSS) injection, e.g., because comments are mishandled.EPSS 0.3%CVE-2026-75010MEDIUMIn Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the modoboa driver of the password plugin could leak a Modoboa API authenticationEPSS 0.3%CVE-2025-68460HIGHRoundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a information disclosure vulnerability in the HTML style sanitizer.EPSS 0.3%CVE-2026-75004MEDIUMIn Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper rule name quoting could lead to managesieve_disabled_actions setting bypEPSS 0.3%CVE-2026-48843HIGHRoundcube Webmail 1.6.x between 1.6.14 and 1.6.16,and 1.7.x before 1.7.1 has Insufficient Cascading Style Sheets (CSS) sanitization in HTML EPSS 0.3%CVE-2026-35539MEDIUMAn issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. XSS exists because of insufficient HTML attachment sanitization in prEPSS 0.3%CVE-2026-62643HIGHIn Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages maEPSS 0.2%CVE-2026-35541MEDIUMAn issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Incorrect password comparison in the password plugin could lead to tyEPSS 0.2%CVE-2026-48849MEDIUMIn Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, an unsanitized subject field in the draft restored value could lead to storEPSS 0.2%CVE-2026-74999MEDIUMIn Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the "Add to address book" action was subject to stored XSS.EPSS 0.2%CVE-2026-54432MEDIUMRoundcube Webmail before 1.6.17 and 1.7.x before 1.7.2 allows Stored Cross-Site Scripting (XSS). The issue occurs because the attachment MIMEPSS 0.2%