Exposição de RoundCube

Webmail
119
score de exposição
1.434
sites usam
3
em exploração
1
críticos
Análise Vexday

RoundCube apresenta uma taxa de exploração ativa expressivamente acima da média do catálogo CISA KEV, com 3 de suas 23 CVEs catalogadas confirmadas em uso por agentes maliciosos — proporção 29 vezes superior à média geral, o que indica histórico concreto de aproveitamento oportunista dessa superfície de ataque. O volume recente é igualmente preocupante: 17 vulnerabilidades surgiram nos últimos 90 dias, sugerindo aumento relevante na atenção de pesquisadores e atacantes à plataforma. A CVE mais crítica atualmente ativa, CVE-2025-49113, registra EPSS de 0,89, valor próximo ao teto da escala, sinalizando altíssima probabilidade de exploração iminente ou em curso. Equipes responsáveis por instâncias RoundCube devem tratar a aplicação de patches como prioridade imediata, com atenção especial às falhas classificadas sob CWE-669, padrão de fraqueza dominante no conjunto de vulnerabilidades desta tecnologia.

CVEs

39 resultados
CVE-2025-49113CRITICALRoundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in aEPSS 98.9%KEVCVE-2023-5631MEDIUMStored XSS vulnerability in RoundcubeEPSS 75.9%KEVCVE-2025-68461HIGHRoundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG dEPSS 26.8%KEVCVE-2026-75002HIGHIn Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, mail search and LITERAL+ byte-count desynchronization could lead to information dEPSS 1.4%CVE-2026-74997HIGHIn Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the cmd_learn driver of the markasjunk plugin is subject to remote code executionEPSS 0.8%CVE-2026-48842HIGHRoundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via a preg_reEPSS 0.8%CVE-2026-25916MEDIUMRoundcube Webmail before 1.5.13 and 1.6 before 1.6.13, when "Block remote images" is used, does not block SVG feImage.EPSS 0.7%CVE-2026-62642MEDIUMIn Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, an infinite loop was discovered in the TNEF decoder, which may lead to denial of EPSS 0.5%CVE-2026-62644MEDIUMIn Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing viaEPSS 0.5%CVE-2026-35537LOWAn issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsafe deserialization in the redis/memcache session handler may leadEPSS 0.5%CVE-2026-62641MEDIUMIn Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the TNEF decoder was subject to denial of service via a crafted compressed-RTF siEPSS 0.5%CVE-2026-48847LOWRoundcube Webmail 1.6.x before 1.6.16, and 1.7.x before 1.7.1 allows pre-authentication arbitrary file deletion via redis/memcache session pEPSS 0.4%CVE-2026-75006MEDIUMIn Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages maEPSS 0.4%CVE-2026-48844HIGHRoundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has insecure code evaluation logic in LDAP the autovalues option that could leaEPSS 0.4%CVE-2026-48846MEDIUMIn Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, the remote image blocking feature can be bypassed via a crafted CSS var() vEPSS 0.4%CVE-2026-35542MEDIUMAn issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via a crafted backgEPSS 0.4%CVE-2026-35543MEDIUMAn issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via SVG content (wiEPSS 0.4%CVE-2026-75003MEDIUMIn Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed url() in a FuncIRI attribute of an SVG image could evade the remote iEPSS 0.4%CVE-2026-35545MEDIUMAn issue was discovered in Roundcube Webmail before 1.5.15 and 1.6.15. The remote image blocking feature can be bypassed via SVG content in EPSS 0.4%CVE-2026-48848HIGHRoundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7 has insufficient HTML sanitization that could lead to Cascading Style Sheets (CSSEPSS 0.4%