<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Roundcube Webmail</title>
  <link>https://cvedaily.com/pages/tags/roundcube.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/roundcube.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Roundcube Webmail</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:41 +0000</lastBuildDate>
  <item>
    <title>[Medium] CVE-2026-9818 – Roundcube's HTML sanitization path for message rendering allows loopback, localh...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9818</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9818</guid>
    <pubDate>Thu, 28 May 2026 13:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9818</strong></p>
  <p>Roundcube's HTML sanitization path for message rendering allows loopback, localhost, RFC1918, link-local, and ULA URLs even when remote content loading is disabled. A remote attacker can send an HTML email that causes the victim's browser to issue requests to local or private-network services simply by opening the message preview.</p>
  <p><strong>CVSS:</strong> 4.7 · <strong>CWE:</strong> CWE-184</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9818">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-48849 – In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, an unsanitized ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48849</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48849</guid>
    <pubDate>Mon, 25 May 2026 20:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-48849</strong></p>
  <p>In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, an unsanitized subject field in the draft restored value could lead to stored XSS/HTML/CSS injection on shared mailboxes.</p>
  <p><strong>CVSS:</strong> 4.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48849">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-48848 – Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7 has insufficient HTML...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48848</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48848</guid>
    <pubDate>Mon, 25 May 2026 20:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-48848</strong></p>
  <p>Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7 has insufficient HTML sanitization that could lead to Cascading Style Sheets (CSS) injection via an SVG document that has an animate element with the attributeName attribute.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48848">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-48847 – Roundcube Webmail 1.6.x before 1.6.16, and 1.7.x before 1.7.1 allows pre-authent...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48847</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48847</guid>
    <pubDate>Mon, 25 May 2026 20:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-48847</strong></p>
  <p>Roundcube Webmail 1.6.x before 1.6.16, and 1.7.x before 1.7.1 allows pre-authentication arbitrary file deletion via redis/memcache session poisoning bypass.</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-669</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48847">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-48846 – In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, the remote imag...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48846</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48846</guid>
    <pubDate>Mon, 25 May 2026 20:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-48846</strong></p>
  <p>In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, the remote image blocking feature can be bypassed via a crafted CSS var() value in an e-mail message, which may lead to information disclosure or access-control bypass.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-669</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48846">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-48845 – In Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16 and 1.7.x before 1.7.1, rem...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48845</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48845</guid>
    <pubDate>Mon, 25 May 2026 20:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-48845</strong></p>
  <p>In Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16 and 1.7.x before 1.7.1, remote image blocking was not honored for URLs pointing to local/private destinations, which may lead to information disclosure or privilege escalation via a text/html email message.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-669</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48845">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-48844 – Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has insecure code e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48844</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48844</guid>
    <pubDate>Mon, 25 May 2026 20:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-48844</strong></p>
  <p>Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has insecure code evaluation logic in LDAP the autovalues option that could lead to code injection. (Support for code evaluation has been removed in 1.6.16 and 1.7.1.)</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-670</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48844">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-48843 – Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16,and 1.7.x before 1.7.1 has Ins...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48843</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48843</guid>
    <pubDate>Mon, 25 May 2026 20:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-48843</strong></p>
  <p>Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16,and 1.7.x before 1.7.1 has Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. The issue stems from an insufficient fix for CVE-2026-35540.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48843">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-48842 – Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authenticat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48842</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48842</guid>
    <pubDate>Mon, 25 May 2026 20:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-48842</strong></p>
  <p>Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via a preg_replace() backslash escape bypass.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48842">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-35545 – An issue was discovered in Roundcube Webmail before 1.5.15 and 1.6.15. The remot...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35545</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35545</guid>
    <pubDate>Fri, 03 Apr 2026 05:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-35545</strong></p>
  <p>An issue was discovered in Roundcube Webmail before 1.5.15 and 1.6.15. The remote image blocking feature can be bypassed via SVG content in an e-mail message. This may lead to information disclosure or access-control bypass. This involves the animate element with attributeName=fill/filter/stroke.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-669</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35545">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-35544 – An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Insuffici...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35544</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35544</guid>
    <pubDate>Fri, 03 Apr 2026 05:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-35544</strong></p>
  <p>An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to a fixed-position mitigation bypass via the use of !important.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-669</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35544">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-35543 – An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remot...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35543</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35543</guid>
    <pubDate>Fri, 03 Apr 2026 05:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-35543</strong></p>
  <p>An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via SVG content (with animate attributes) in an e-mail message. This may lead to information disclosure or access-control bypass.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-669</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35543">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-35542 – An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remot...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35542</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35542</guid>
    <pubDate>Fri, 03 Apr 2026 05:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-35542</strong></p>
  <p>An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via a crafted background attribute of a BODY element in an e-mail message. This may lead to information disclosure or access-control bypass.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-669</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35542">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-35541 – An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Incorrect...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35541</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35541</guid>
    <pubDate>Fri, 03 Apr 2026 05:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-35541</strong></p>
  <p>An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Incorrect password comparison in the password plugin could lead to type confusion that allows a password change without knowing the old password.</p>
  <p><strong>CVSS:</strong> 4.2 · <strong>CWE:</strong> CWE-843</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35541">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-35540 – An issue was discovered in Roundcube Webmail 1.6.0 before 1.6.14. Insufficient C...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35540</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35540</guid>
    <pubDate>Fri, 03 Apr 2026 05:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-35540</strong></p>
  <p>An issue was discovered in Roundcube Webmail 1.6.0 before 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-669</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35540">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-35539 – An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. XSS exist...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35539</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35539</guid>
    <pubDate>Fri, 03 Apr 2026 05:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-35539</strong></p>
  <p>An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. XSS exists because of insufficient HTML attachment sanitization in preview mode. A victim must preview a text/html attachment.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35539">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-35538 – An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsanitiz...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35538</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35538</guid>
    <pubDate>Fri, 03 Apr 2026 05:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-35538</strong></p>
  <p>An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsanitized IMAP SEARCH command arguments could lead to IMAP injection or CSRF bypass during mail search.</p>
  <p><strong>CVSS:</strong> 3.1 · <strong>CWE:</strong> CWE-88</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35538">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-35537 – An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsafe de...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35537</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35537</guid>
    <pubDate>Fri, 03 Apr 2026 04:17:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-35537</strong></p>
  <p>An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsafe deserialization in the redis/memcache session handler may lead to arbitrary file write operations by unauthenticated attackers via crafted session data.</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35537">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-26079 – Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13 allows Cascading Style She...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26079</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26079</guid>
    <pubDate>Wed, 11 Feb 2026 05:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-26079</strong></p>
  <p>Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13 allows Cascading Style Sheets (CSS) injection, e.g., because comments are mishandled.</p>
  <p><strong>CVSS:</strong> 4.7 · <strong>CWE:</strong> CWE-829</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26079">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-25916 – Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13, when "Block remote images...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25916</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25916</guid>
    <pubDate>Mon, 09 Feb 2026 09:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-25916</strong></p>
  <p>Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13, when "Block remote images" is used, does not block SVG feImage.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-420</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25916">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-68461 – Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-68461</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-68461</guid>
    <pubDate>Thu, 18 Dec 2025 05:15:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-68461</strong></p>
  <p>Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68461">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-68460 – Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a information ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-68460</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-68460</guid>
    <pubDate>Thu, 18 Dec 2025 05:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-68460</strong></p>
  <p>Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a information disclosure vulnerability in the HTML style sanitizer.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-116</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68460">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-49113 – Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-49113</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-49113</guid>
    <pubDate>Mon, 02 Jun 2025 05:15:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-49113</strong></p>
  <p>Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP Object Deserialization.</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-49113">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-57004 – Cross-Site Scripting (XSS) vulnerability in Roundcube Webmail 1.6.9 allows remot...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-57004</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-57004</guid>
    <pubDate>Mon, 03 Feb 2025 19:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-57004</strong></p>
  <p>Cross-Site Scripting (XSS) vulnerability in Roundcube Webmail 1.6.9 allows remote authenticated users to upload a malicious file as an email attachment, leading to the triggering of the XSS by visiting the SENT session.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-80</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-57004">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-42010 – mod_css_styles in Roundcube through 1.5.7 and 1.6.x through 1.6.7 insufficiently...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-42010</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-42010</guid>
    <pubDate>Mon, 05 Aug 2024 19:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-42010</strong></p>
  <p>mod_css_styles in Roundcube through 1.5.7 and 1.6.x through 1.6.7 insufficiently filters Cascading Style Sheets (CSS) token sequences in rendered e-mail messages, allowing a remote attacker to obtain sensitive information.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-42010">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-42009 – A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x throug...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-42009</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-42009</guid>
    <pubDate>Mon, 05 Aug 2024 19:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-42009</strong></p>
  <p>A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a crafted e-mail message that abuses a Desanitization issue in message_body() in program/actions/mail/show.php.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-42009">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-42008 – A Cross-Site Scripting vulnerability in rcmail_action_mail_get-&gt;run() in Roundcu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-42008</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-42008</guid>
    <pubDate>Mon, 05 Aug 2024 19:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-42008</strong></p>
  <p>A Cross-Site Scripting vulnerability in rcmail_action_mail_get->run() in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a malicious e-mail attachment served with a dangerous Content-Type header.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-42008">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-37385 – Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 on Windows allows command ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-37385</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-37385</guid>
    <pubDate>Fri, 07 Jun 2024 04:15:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-37385</strong></p>
  <p>Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 on Windows allows command injection via im_convert_path and im_identify_path. NOTE: this issue exists because of an incomplete fix for CVE-2020-12641.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-37385">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-37384 – Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via list column...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-37384</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-37384</guid>
    <pubDate>Fri, 07 Jun 2024 04:15:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-37384</strong></p>
  <p>Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via list columns from user preferences.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-37384">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-37383 – Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-37383</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-37383</guid>
    <pubDate>Fri, 07 Jun 2024 04:15:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-37383</strong></p>
  <p>Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-37383">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-47272 – Roundcube 1.5.x before 1.5.6 and 1.6.x before 1.6.5 allows XSS via a Content-Typ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-47272</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-47272</guid>
    <pubDate>Mon, 06 Nov 2023 00:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-47272</strong></p>
  <p>Roundcube 1.5.x before 1.5.6 and 1.6.x before 1.6.5 allows XSS via a Content-Type or Content-Disposition header (used for attachment preview or download).</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-47272">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-5631 – Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows store...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-5631</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-5631</guid>
    <pubDate>Wed, 18 Oct 2023 15:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-5631</strong></p>
  <p>Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a crafted SVG document because of program/lib/Roundcube/rcube_washtml.php behavior. This could allow a remote attacker  to load arbitrary JavaScript code.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-5631">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-43770 – Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-43770</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-43770</guid>
    <pubDate>Fri, 22 Sep 2023 06:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-43770</strong></p>
  <p>Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of program/lib/Roundcube/rcube_string_replacer.php behavior.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-43770">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-3222 – Vulnerability in the password recovery mechanism of Password Recovery plugin for...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-3222</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-3222</guid>
    <pubDate>Mon, 04 Sep 2023 13:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-3222</strong></p>
  <p>Vulnerability in the password recovery mechanism of Password Recovery plugin for Roundcube, in its 1.2 version, which could allow a remote attacker to change an existing user´s password by adding a 6-digit numeric token. An attacker could create an automatic script to test all possible values because the platform has no limit on the number of requests.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-3222">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-3221 – User enumeration vulnerability in Password Recovery plugin 1.2 version for Round...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-3221</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-3221</guid>
    <pubDate>Mon, 04 Sep 2023 13:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-3221</strong></p>
  <p>User enumeration vulnerability in Password Recovery plugin 1.2 version for Roundcube, which could allow a remote attacker to create a test script against the password recovery function to enumerate all users in the database.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-204</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-3221">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-28218 – An issue was discovered in CipherMail Webmail Messenger 1.1.1 through 4.1.4. A l...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-28218</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-28218</guid>
    <pubDate>Tue, 26 Apr 2022 18:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-28218</strong></p>
  <p>An issue was discovered in CipherMail Webmail Messenger 1.1.1 through 4.1.4. A local attacker could access secret keys (found in a Roundcube configuration file) that are used to protect Webmail user passwords and two-factor authentication (2FA).</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-28218">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-46144 – Roundcube before 1.4.13 and 1.5.x before 1.5.2 allows XSS via an HTML e-mail mes...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-46144</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-46144</guid>
    <pubDate>Thu, 06 Jan 2022 05:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-46144</strong></p>
  <p>Roundcube before 1.4.13 and 1.5.x before 1.5.2 allows XSS via an HTML e-mail message with crafted Cascading Style Sheets (CSS) token sequences.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-46144">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-44026 – Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL inje...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-44026</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-44026</guid>
    <pubDate>Fri, 19 Nov 2021 04:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-44026</strong></p>
  <p>Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-44026">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-44025 – Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to XSS in handling an a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-44025</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-44025</guid>
    <pubDate>Fri, 19 Nov 2021 04:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-44025</strong></p>
  <p>Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to XSS in handling an attachment's filename extension when displaying a MIME type warning message.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-44025">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-18671 – Cross Site Scripting (XSS) vulnerability in Roundcube Mail &lt;=1.4.4 via smtp conf...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-18671</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-18671</guid>
    <pubDate>Thu, 24 Jun 2021 19:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-18671</strong></p>
  <p>Cross Site Scripting (XSS) vulnerability in Roundcube Mail <=1.4.4 via smtp config in /installer/test.php.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-18671">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-18670 – Cross Site Scripting (XSS) vulneraibility in Roundcube mail .4.4 via database ho...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-18670</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-18670</guid>
    <pubDate>Thu, 24 Jun 2021 19:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-18670</strong></p>
  <p>Cross Site Scripting (XSS) vulneraibility in Roundcube mail .4.4 via database host and user in /installer/test.php.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-18670">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-26925 – Roundcube before 1.4.11 allows XSS via crafted Cascading Style Sheets (CSS) toke...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-26925</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-26925</guid>
    <pubDate>Tue, 09 Feb 2021 09:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-26925</strong></p>
  <p>Roundcube before 1.4.11 allows XSS via crafted Cascading Style Sheets (CSS) token sequences during HTML email rendering.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-26925">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-35730 – An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-35730</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-35730</guid>
    <pubDate>Mon, 28 Dec 2020 20:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-35730</strong></p>
  <p>An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attacker can send a plain text e-mail message, with JavaScript in a link reference element that is mishandled by linkref_addindex in rcube_string_replacer.php.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-35730">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-16145 – Roundcube Webmail before 1.3.15 and 1.4.8 allows stored XSS in HTML messages dur...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-16145</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-16145</guid>
    <pubDate>Wed, 12 Aug 2020 13:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-16145</strong></p>
  <p>Roundcube Webmail before 1.3.15 and 1.4.8 allows stored XSS in HTML messages during message display via a crafted SVG document. This issue has been fixed in 1.4.8 and 1.3.15.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-16145">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-15562 – An issue was discovered in Roundcube Webmail before 1.2.11, 1.3.x before 1.3.14,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15562</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15562</guid>
    <pubDate>Mon, 06 Jul 2020 12:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-15562</strong></p>
  <p>An issue was discovered in Roundcube Webmail before 1.2.11, 1.3.x before 1.3.14, and 1.4.x before 1.4.7. It allows XSS via a crafted HTML e-mail message, as demonstrated by a JavaScript payload in the xmlns (aka XML namespace) attribute of a HEAD element when an SVG element exists.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15562">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-13965 – An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-13965</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-13965</guid>
    <pubDate>Tue, 09 Jun 2020 03:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-13965</strong></p>
  <p>An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is among the allowed types for a preview.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-13965">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-13964 – An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-13964</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-13964</guid>
    <pubDate>Tue, 09 Jun 2020 03:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-13964</strong></p>
  <p>An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. include/rcmail_output_html.php allows XSS via the username template object.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-13964">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-12641 – rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute ar...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-12641</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-12641</guid>
    <pubDate>Mon, 04 May 2020 15:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-12641</strong></p>
  <p>rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setting for im_convert_path or im_identify_path.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-12641">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-12640 – Roundcube Webmail before 1.4.4 allows attackers to include local files and execu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-12640</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-12640</guid>
    <pubDate>Mon, 04 May 2020 15:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-12640</strong></p>
  <p>Roundcube Webmail before 1.4.4 allows attackers to include local files and execute code via directory traversal in a plugin name to rcube_plugin_api.php.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-12640">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-12626 – An issue was discovered in Roundcube Webmail before 1.4.4. A CSRF attack can cau...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-12626</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-12626</guid>
    <pubDate>Mon, 04 May 2020 02:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-12626</strong></p>
  <p>An issue was discovered in Roundcube Webmail before 1.4.4. A CSRF attack can cause an authenticated user to be logged out because POST was not considered.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-12626">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-12625 – An issue was discovered in Roundcube Webmail before 1.4.4. There is a cross-site...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-12625</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-12625</guid>
    <pubDate>Mon, 04 May 2020 02:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-12625</strong></p>
  <p>An issue was discovered in Roundcube Webmail before 1.4.4. There is a cross-site scripting (XSS) vulnerability in rcube_washtml.php because JavaScript code can occur in the CDATA of an HTML message.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-12625">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-15237 – Roundcube Webmail through 1.3.9 mishandles Punycode xn-- domain names, leading t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-15237</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-15237</guid>
    <pubDate>Tue, 20 Aug 2019 01:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-15237</strong></p>
  <p>Roundcube Webmail through 1.3.9 mishandles Punycode xn-- domain names, leading to homograph attacks.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-15237">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-10770 – cPanel before 60.0.25 allows arbitrary file-overwrite operations during a Roundc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-10770</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-10770</guid>
    <pubDate>Mon, 05 Aug 2019 13:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-10770</strong></p>
  <p>cPanel before 60.0.25 allows arbitrary file-overwrite operations during a Roundcube update (SEC-164).</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-10770">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2017-18450 – cPanel before 64.0.21 allows certain file-chmod operations via /scripts/convert_...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-18450</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-18450</guid>
    <pubDate>Fri, 02 Aug 2019 17:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2017-18450</strong></p>
  <p>cPanel before 64.0.21 allows certain file-chmod operations via /scripts/convert_roundcube_mysql2sqlite (SEC-255).</p>
  <p><strong>CVSS:</strong> 4.5 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-18450">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2017-18449 – cPanel before 64.0.21 allows certain file-rename operations in the context of th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-18449</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-18449</guid>
    <pubDate>Fri, 02 Aug 2019 17:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2017-18449</strong></p>
  <p>cPanel before 64.0.21 allows certain file-rename operations in the context of the root account via scripts/convert_roundcube_mysql2sqlite (SEC-254).</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-18449">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2017-18416 – cPanel before 67.9999.103 allows arbitrary file-overwrite operations during a Ro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-18416</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-18416</guid>
    <pubDate>Fri, 02 Aug 2019 14:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2017-18416</strong></p>
  <p>cPanel before 67.9999.103 allows arbitrary file-overwrite operations during a Roundcube SQLite schema update (SEC-303).</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-18416">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-10846 – cPanel before 11.54.0.4 allows arbitrary file-chown and file-chmod operations du...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-10846</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-10846</guid>
    <pubDate>Thu, 01 Aug 2019 16:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-10846</strong></p>
  <p>cPanel before 11.54.0.4 allows arbitrary file-chown and file-chmod operations during Roundcube database conversions (SEC-79).</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-275</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-10846">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-12938 – The Roundcube component of Analogic Poste.io 2.1.6 uses .htaccess to protect the...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-12938</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-12938</guid>
    <pubDate>Mon, 24 Jun 2019 14:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-12938</strong></p>
  <p>The Roundcube component of Analogic Poste.io 2.1.6 uses .htaccess to protect the logs/ folder, which is effective with the Apache HTTP Server but is ineffective with nginx. Attackers can read logs via the webmail/logs/sendmail URI.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-693</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-12938">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-10740 – In Roundcube Webmail before 1.3.10, an attacker in possession of S/MIME or PGP e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-10740</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-10740</guid>
    <pubDate>Sun, 07 Apr 2019 15:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-10740</strong></p>
  <p>In Roundcube Webmail before 1.3.10, an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub-parts within a crafted multipart email. The encrypted part(s) can further be hidden using HTML/CSS or ASCII newline characters. This modified multipart email can be re-sent by the attacker to the intended receiver. If the receiver replies to this (benign looking) email, they unknow…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-319</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-10740">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-19206 – steps/mail/func.inc in Roundcube before 1.3.8 has XSS via crafted use of &lt;svg&gt;&lt;s...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-19206</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-19206</guid>
    <pubDate>Mon, 12 Nov 2018 17:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-19206</strong></p>
  <p>steps/mail/func.inc in Roundcube before 1.3.8 has XSS via crafted use of <svg><style>, as demonstrated by an onload attribute in a BODY element, within an HTML attachment.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-19206">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-19205 – Roundcube before 1.3.7 mishandles GnuPG MDC integrity-protection warnings, which...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-19205</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-19205</guid>
    <pubDate>Mon, 12 Nov 2018 17:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-19205</strong></p>
  <p>Roundcube before 1.3.7 mishandles GnuPG MDC integrity-protection warnings, which makes it easier for attackers to obtain sensitive information, a related issue to CVE-2017-17688. This is associated with plugins/enigma/lib/enigma_driver_gnupg.php.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-19205">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-16736 – In the rcfilters plugin 2.1.6 for Roundcube, XSS exists via the _whatfilter and ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-16736</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-16736</guid>
    <pubDate>Sun, 09 Sep 2018 12:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-16736</strong></p>
  <p>In the rcfilters plugin 2.1.6 for Roundcube, XSS exists via the _whatfilter and _messages parameters (in the Filters section of the settings).</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-16736">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-9846 – In Roundcube from versions 1.2.0 to 1.3.5, with the archive plugin enabled and c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-9846</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-9846</guid>
    <pubDate>Sat, 07 Apr 2018 21:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-9846</strong></p>
  <p>In Roundcube from versions 1.2.0 to 1.3.5, with the archive plugin enabled and configured, it's possible to exploit the unsanitized, user-controlled "_uid" parameter (in an archive.php _task=mail&_mbox=INBOX&_action=plugin.move2archive request) to perform an MX (IMAP) injection attack by placing an IMAP command after a %0d%0a sequence. NOTE: this is less easily exploitable in 1.3.4 and later beca…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-9846">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-1000072 – iRedMail version prior to commit f04b8ef contains a Insecure Permissions vulnera...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1000072</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1000072</guid>
    <pubDate>Tue, 13 Mar 2018 15:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-1000072</strong></p>
  <p>iRedMail version prior to commit f04b8ef contains a Insecure Permissions vulnerability in Roundcube Webmail that can result in Exfiltrate a user's password protected secret GPG key file and other important configuration files.. This attack appear to be exploitable via network connectivity. This vulnerability appears to have been fixed in Beta: 0.9.8-BETA1, Stable: 0.9.7.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1000072">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-1000071 – roundcube version 1.3.4 and earlier contains an Insecure Permissions vulnerabili...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1000071</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1000071</guid>
    <pubDate>Tue, 13 Mar 2018 15:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-1000071</strong></p>
  <p>roundcube version 1.3.4 and earlier contains an Insecure Permissions vulnerability in enigma plugin that can result in exfiltration of gpg private key. This attack appear to be exploitable via network connectivity.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1000071">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-16651 – Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-16651</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-16651</guid>
    <pubDate>Thu, 09 Nov 2017 14:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-16651</strong></p>
  <p>Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's filesystem, including configuration files, as exploited in the wild in November 2017. The attacker must be able to authenticate at the target system with a valid username/password as the attack requires an active session. The issue is related to file-based attach…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-552</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-16651">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-5383 – Roundcube Webmail 1.1.x before 1.1.2 allows remote attackers to obtain sensitive...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-5383</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-5383</guid>
    <pubDate>Tue, 23 May 2017 04:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-5383</strong></p>
  <p>Roundcube Webmail 1.1.x before 1.1.2 allows remote attackers to obtain sensitive information by reading files in the (1) config, (2) temp, or (3) logs directory.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-5383">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2015-5382 – program/steps/addressbook/photo.inc in Roundcube Webmail before 1.0.6 and 1.1.x ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-5382</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-5382</guid>
    <pubDate>Tue, 23 May 2017 04:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2015-5382</strong></p>
  <p>program/steps/addressbook/photo.inc in Roundcube Webmail before 1.0.6 and 1.1.x before 1.1.2 allows remote authenticated users to read arbitrary files via the _alt parameter when uploading a vCard.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-5382">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2015-5381 – Cross-site scripting (XSS) vulnerability in program/include/rcmail.php in Roundc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-5381</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-5381</guid>
    <pubDate>Tue, 23 May 2017 04:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2015-5381</strong></p>
  <p>Cross-site scripting (XSS) vulnerability in program/include/rcmail.php in Roundcube Webmail 1.1.x before 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the _mbox parameter to the default URI.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-5381">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-8114 – Roundcube Webmail allows arbitrary password resets by authenticated users. This ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-8114</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-8114</guid>
    <pubDate>Sat, 29 Apr 2017 19:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-8114</strong></p>
  <p>Roundcube Webmail allows arbitrary password resets by authenticated users. This affects versions before 1.0.11, 1.1.x before 1.1.9, and 1.2.x before 1.2.5. The problem is caused by an improperly restricted exec call in the virtualmin and sasl drivers of the password plugin.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-8114">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-4068 – Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.0.9 and 1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-4068</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-4068</guid>
    <pubDate>Thu, 13 Apr 2017 14:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-4068</strong></p>
  <p>Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.0.9 and 1.1.x before 1.1.5 allows remote attackers to inject arbitrary web script or HTML via a crafted SVG, a different vulnerability than CVE-2015-8864.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-4068">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2015-8864 – Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.0.9 and 1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-8864</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-8864</guid>
    <pubDate>Thu, 13 Apr 2017 14:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2015-8864</strong></p>
  <p>Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.0.9 and 1.1.x before 1.1.5 allows remote attackers to inject arbitrary web script or HTML via a crafted SVG, a different vulnerability than CVE-2016-4068.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-8864">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2017-6820 – rcube_utils.php in Roundcube before 1.1.8 and 1.2.x before 1.2.4 is susceptible ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-6820</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-6820</guid>
    <pubDate>Sun, 12 Mar 2017 05:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2017-6820</strong></p>
  <p>rcube_utils.php in Roundcube before 1.1.8 and 1.2.x before 1.2.4 is susceptible to a cross-site scripting vulnerability via a crafted Cascading Style Sheets (CSS) token sequence within an SVG element.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-6820">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-2181 – Multiple buffer overflows in the DBMail driver in the Password plugin in Roundcu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-2181</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-2181</guid>
    <pubDate>Mon, 30 Jan 2017 22:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-2181</strong></p>
  <p>Multiple buffer overflows in the DBMail driver in the Password plugin in Roundcube before 1.1.0 allow remote attackers to have unspecified impact via the (1) password or (2) username.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-2181">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-2180 – The DBMail driver in the Password plugin in Roundcube before 1.1.0 allows remote...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-2180</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-2180</guid>
    <pubDate>Mon, 30 Jan 2017 22:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-2180</strong></p>
  <p>The DBMail driver in the Password plugin in Roundcube before 1.1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the password.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-2180">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-4552 – Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.2.0 allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-4552</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-4552</guid>
    <pubDate>Tue, 20 Dec 2016 22:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-4552</strong></p>
  <p>Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.2.0 allows remote attackers to inject arbitrary web script or HTML via the href attribute in an area tag in an e-mail message.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-4552">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-9920 – steps/mail/sendmail.inc in Roundcube before 1.1.7 and 1.2.x before 1.2.3, when n...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-9920</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-9920</guid>
    <pubDate>Thu, 08 Dec 2016 18:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-9920</strong></p>
  <p>steps/mail/sendmail.inc in Roundcube before 1.1.7 and 1.2.x before 1.2.3, when no SMTP server is configured and the sendmail program is enabled, does not properly restrict the use of custom envelope-from addresses on the sendmail command line, which allows remote authenticated users to execute arbitrary code via a modified HTTP request that sends a crafted e-mail message.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-9920">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-4069 – Cross-site request forgery (CSRF) vulnerability in Roundcube Webmail before 1.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-4069</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-4069</guid>
    <pubDate>Thu, 25 Aug 2016 18:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-4069</strong></p>
  <p>Cross-site request forgery (CSRF) vulnerability in Roundcube Webmail before 1.1.5 allows remote attackers to hijack the authentication of users for requests that download attachments and cause a denial of service (disk consumption) via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-4069">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2015-8794 – Absolute path traversal vulnerability in program/steps/addressbook/photo.inc in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-8794</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-8794</guid>
    <pubDate>Fri, 29 Jan 2016 19:59:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2015-8794</strong></p>
  <p>Absolute path traversal vulnerability in program/steps/addressbook/photo.inc in Roundcube before 1.0.6 and 1.1.x before 1.1.2 allows remote authenticated users to read arbitrary files via a full pathname in the _alt parameter, related to contact photo handling.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-8794">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2015-8793 – Cross-site scripting (XSS) vulnerability in program/include/rcmail.php in Roundc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-8793</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-8793</guid>
    <pubDate>Fri, 29 Jan 2016 19:59:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2015-8793</strong></p>
  <p>Cross-site scripting (XSS) vulnerability in program/include/rcmail.php in Roundcube before 1.0.6 and 1.1.x before 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the _mbox parameter in a mail task to the default URL, a different vulnerability than CVE-2011-2937.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-8793">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-8770 – Directory traversal vulnerability in the set_skin function in program/include/rc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-8770</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-8770</guid>
    <pubDate>Fri, 29 Jan 2016 19:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-8770</strong></p>
  <p>Directory traversal vulnerability in the set_skin function in program/include/rcmail_output_html.php in Roundcube before 1.0.8 and 1.1.x before 1.1.4 allows remote authenticated users with certain permissions to read arbitrary files or possibly execute arbitrary code via a .. (dot dot) in the _skin parameter to index.php.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-8770">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2015-8105 – Cross-site scripting (XSS) vulnerability in program/js/app.js in Roundcube webma...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-8105</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-8105</guid>
    <pubDate>Tue, 10 Nov 2015 17:59:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2015-8105</strong></p>
  <p>Cross-site scripting (XSS) vulnerability in program/js/app.js in Roundcube webmail before 1.0.7 and 1.1.x before 1.1.3 allows remote authenticated users to inject arbitrary web script or HTML via the file name in a drag-n-drop file upload.</p>
  <p><strong>CVSS:</strong> 3.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-8105">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2015-1433 – program/lib/Roundcube/rcube_washtml.php in Roundcube before 1.0.5 does not prope...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-1433</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-1433</guid>
    <pubDate>Tue, 03 Feb 2015 16:59:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2015-1433</strong></p>
  <p>program/lib/Roundcube/rcube_washtml.php in Roundcube before 1.0.5 does not properly quote strings, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the style attribute in an email.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-1433">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2014-9587 – Multiple cross-site request forgery (CSRF) vulnerabilities in Roundcube Webmail ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-9587</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-9587</guid>
    <pubDate>Thu, 15 Jan 2015 15:59:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2014-9587</strong></p>
  <p>Multiple cross-site request forgery (CSRF) vulnerabilities in Roundcube Webmail before 1.0.4 allow remote attackers to hijack the authentication of unspecified victims via unknown vectors, related to (1) address book operations or the (2) ACL or (3) Managesieve plugins.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-9587">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2013-1904 – Absolute path traversal vulnerability in steps/mail/sendmail.inc in Roundcube We...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-1904</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-1904</guid>
    <pubDate>Sat, 08 Feb 2014 00:55:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2013-1904</strong></p>
  <p>Absolute path traversal vulnerability in steps/mail/sendmail.inc in Roundcube Webmail before 0.7.3 and 0.8.x before 0.8.6 allows remote attackers to read arbitrary files via a full pathname in the _value parameter for the generic_message_footer setting in a save-perf action to index.php, as exploited in the wild in March 2013.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-1904">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2013-6172 – steps/utils/save_pref.inc in Roundcube webmail before 0.8.7 and 0.9.x before 0.9...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-6172</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-6172</guid>
    <pubDate>Tue, 05 Nov 2013 18:55:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2013-6172</strong></p>
  <p>steps/utils/save_pref.inc in Roundcube webmail before 0.8.7 and 0.9.x before 0.9.5 allows remote attackers to modify configuration settings via the _session parameter, which can be leveraged to read arbitrary files, conduct SQL injection attacks, and execute arbitrary code.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-6172">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2013-5646 – Cross-site scripting (XSS) vulnerability in Roundcube webmail 1.0-git allows rem...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-5646</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-5646</guid>
    <pubDate>Thu, 29 Aug 2013 12:07:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2013-5646</strong></p>
  <p>Cross-site scripting (XSS) vulnerability in Roundcube webmail 1.0-git allows remote authenticated users to inject arbitrary web script or HTML via the Name field of an addressbook group.</p>
  <p><strong>CVSS:</strong> 3.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-5646">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2013-5645 – Multiple cross-site scripting (XSS) vulnerabilities in Roundcube webmail before ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-5645</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-5645</guid>
    <pubDate>Thu, 29 Aug 2013 12:07:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2013-5645</strong></p>
  <p>Multiple cross-site scripting (XSS) vulnerabilities in Roundcube webmail before 0.9.3 allow user-assisted remote attackers to inject arbitrary web script or HTML via the body of a message visited in (1) new or (2) draft mode, related to compose.inc; and (3) might allow remote authenticated users to inject arbitrary web script or HTML via an HTML signature, related to save_identity.inc.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-5645">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2012-6121 – Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 0.8.5 allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-6121</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-6121</guid>
    <pubDate>Sun, 24 Feb 2013 21:55:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2012-6121</strong></p>
  <p>Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 0.8.5 allows remote attackers to inject arbitrary web script or HTML via a (1) data:text or (2) vbscript link.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-6121">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2012-4668 – Cross-site scripting (XSS) vulnerability in Roundcube Webmail 0.8.1 and earlier ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-4668</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-4668</guid>
    <pubDate>Sat, 25 Aug 2012 10:29:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2012-4668</strong></p>
  <p>Cross-site scripting (XSS) vulnerability in Roundcube Webmail 0.8.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the signature in an email.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-4668">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2012-3508 – Cross-site scripting (XSS) vulnerability in program/lib/washtml.php in Roundcube...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-3508</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-3508</guid>
    <pubDate>Sat, 25 Aug 2012 10:29:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2012-3508</strong></p>
  <p>Cross-site scripting (XSS) vulnerability in program/lib/washtml.php in Roundcube Webmail 0.8.0 allows remote attackers to inject arbitrary web script or HTML by using "javascript:" in an href attribute in the body of an HTML-formatted email.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-3508">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2012-3507 – Cross-site scripting (XSS) vulnerability in program/steps/mail/func.inc in Round...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-3507</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-3507</guid>
    <pubDate>Sat, 25 Aug 2012 10:29:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2012-3507</strong></p>
  <p>Cross-site scripting (XSS) vulnerability in program/steps/mail/func.inc in RoundCube Webmail before 0.8.0, when using the Larry skin, allows remote attackers to inject arbitrary web script or HTML via the email message subject.</p>
  <p><strong>CVSS:</strong> 2.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-3507">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2012-1253 – Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 0.7, when I...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-1253</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-1253</guid>
    <pubDate>Mon, 04 Jun 2012 15:55:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2012-1253</strong></p>
  <p>Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 0.7, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via vectors involving an embedded image attachment.</p>
  <p><strong>CVSS:</strong> 2.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-1253">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2011-4078 – include/iniset.php in Roundcube Webmail 0.5.4 and earlier, when PHP 5.3.7 or 5.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4078</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4078</guid>
    <pubDate>Thu, 03 Nov 2011 15:55:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2011-4078</strong></p>
  <p>include/iniset.php in Roundcube Webmail 0.5.4 and earlier, when PHP 5.3.7 or 5.3.8 is used, allows remote attackers to trigger a GET request for an arbitrary URL, and cause a denial of service (resource consumption and inbox outage), via a Subject header containing only a URL, a related issue to CVE-2011-3379.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4078">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2011-2937 – Cross-site scripting (XSS) vulnerability in the UI messages functionality in Rou...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-2937</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-2937</guid>
    <pubDate>Wed, 21 Sep 2011 16:55:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2011-2937</strong></p>
  <p>Cross-site scripting (XSS) vulnerability in the UI messages functionality in Roundcube Webmail before 0.5.4 allows remote attackers to inject arbitrary web script or HTML via the _mbox parameter to the default URI.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-2937">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2011-1492 – steps/utils/modcss.inc in Roundcube Webmail before 0.5.1 does not properly verif...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-1492</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-1492</guid>
    <pubDate>Fri, 08 Apr 2011 15:17:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2011-1492</strong></p>
  <p>steps/utils/modcss.inc in Roundcube Webmail before 0.5.1 does not properly verify that a request is an expected request for an external Cascading Style Sheets (CSS) stylesheet, which allows remote authenticated users to trigger arbitrary outbound TCP connections from the server, and possibly obtain sensitive information, via a crafted request.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-1492">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2011-1491 – The login form in Roundcube Webmail before 0.5.1 does not properly handle a corr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-1491</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-1491</guid>
    <pubDate>Fri, 08 Apr 2011 15:17:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2011-1491</strong></p>
  <p>The login form in Roundcube Webmail before 0.5.1 does not properly handle a correctly authenticated but unintended login attempt, which makes it easier for remote authenticated users to obtain sensitive information by arranging for a victim to login to the attacker's account and then compose an e-mail message, related to a "login CSRF" issue.</p>
  <p><strong>CVSS:</strong> 3.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-1491">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2010-0464 – Roundcube 0.3.1 and earlier does not request that the web browser avoid DNS pref...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-0464</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-0464</guid>
    <pubDate>Fri, 29 Jan 2010 18:30:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2010-0464</strong></p>
  <p>Roundcube 0.3.1 and earlier does not request that the web browser avoid DNS prefetching of domain names contained in e-mail messages, which makes it easier for remote attackers to determine the network location of the webmail user by logging DNS requests.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-0464">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2009-4077 – Cross-site request forgery (CSRF) vulnerability in Roundcube Webmail 0.2.2 and e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-4077</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-4077</guid>
    <pubDate>Wed, 25 Nov 2009 22:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2009-4077</strong></p>
  <p>Cross-site request forgery (CSRF) vulnerability in Roundcube Webmail 0.2.2 and earlier allows remote attackers to hijack the authentication of unspecified users for requests that send arbitrary emails via unspecified vectors, a different vulnerability than CVE-2009-4076.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-4077">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2009-4076 – Cross-site request forgery (CSRF) vulnerability in Roundcube Webmail 0.2.2 and e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-4076</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-4076</guid>
    <pubDate>Wed, 25 Nov 2009 22:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2009-4076</strong></p>
  <p>Cross-site request forgery (CSRF) vulnerability in Roundcube Webmail 0.2.2 and earlier allows remote attackers to hijack the authentication of unspecified users for requests that modify user information via unspecified vectors, a different vulnerability than CVE-2009-4077.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-4076">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
