Vulnerabilidades en Roundcube
39 resultadosAnálisis Vexday
Roundcube apresenta 29 vulnerabilidades catalogadas, com 14 divulgadas nos últimos 90 dias indicando ritmo elevado de descobertas recentes; 3 estão sob exploração ativa (KEV), embora apenas 1 seja crítica. A fraqueza dominante é CWE-669 (configuração imprópria), sugerindo que o risco concentra-se mais em má configuração e exposição do que em falhas de código severas.
CVE-2025-49113CRITICALRoundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in aEPSS 98.9%KEVCVE-2023-5631MEDIUMStored XSS vulnerability in RoundcubeEPSS 75.9%KEVCVE-2025-68461HIGHRoundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG dEPSS 26.8%KEVCVE-2026-75002HIGHIn Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, mail search and LITERAL+ byte-count desynchronization could lead to information dEPSS 2.3%CVE-2026-74997HIGHIn Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the cmd_learn driver of the markasjunk plugin is subject to remote code executionEPSS 1.1%CVE-2026-48842HIGHRoundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via a preg_reEPSS 0.9%CVE-2026-35537LOWAn issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsafe deserialization in the redis/memcache session handler may leadEPSS 0.6%CVE-2026-75003MEDIUMIn Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed url() in a FuncIRI attribute of an SVG image could evade the remote iEPSS 0.6%CVE-2026-75006MEDIUMIn Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages maEPSS 0.6%CVE-2026-35545MEDIUMAn issue was discovered in Roundcube Webmail before 1.5.15 and 1.6.15. The remote image blocking feature can be bypassed via SVG content in EPSS 0.5%CVE-2026-48847LOWRoundcube Webmail 1.6.x before 1.6.16, and 1.7.x before 1.7.1 allows pre-authentication arbitrary file deletion via redis/memcache session pEPSS 0.5%CVE-2026-35543MEDIUMAn issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via SVG content (wiEPSS 0.5%CVE-2026-35542MEDIUMAn issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via a crafted backgEPSS 0.5%CVE-2026-62642MEDIUMIn Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, an infinite loop was discovered in the TNEF decoder, which may lead to denial of EPSS 0.5%CVE-2026-26079MEDIUMRoundcube Webmail before 1.5.13 and 1.6 before 1.6.13 allows Cascading Style Sheets (CSS) injection, e.g., because comments are mishandled.EPSS 0.5%CVE-2026-48844HIGHRoundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has insecure code evaluation logic in LDAP the autovalues option that could leaEPSS 0.5%CVE-2026-35544MEDIUMAn issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mailEPSS 0.5%CVE-2026-75007MEDIUMIn Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the LDAP search filter was subject to injection via unescaped %u/%fu/%d substitutEPSS 0.5%CVE-2026-62644MEDIUMIn Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing viaEPSS 0.5%CVE-2026-48846MEDIUMIn Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, the remote image blocking feature can be bypassed via a crafted CSS var() vEPSS 0.5%