roundcube/roundcubemail
The Roundcube Webmail suite
Activity
- Latest release
- 1w ago
- Total releases
- 13
- Cadence
- ~33 days
- Last 12 months
- 12
Reach
- Stars
- 7.2k
Details
- License
- unknown
- First release
- Jul 07, 2025
| Version | Released | |
|---|---|---|
1.7.4
patch
|
1.7.4
patch
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
1.7.3
patch
|
1.7.3
patch
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
1.7.2
patch
|
1.7.2
patch
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
1.7.1
patch
| ||
1.7.0
initial
| ||
1.7-rc6
pre
|
1.7-rc6
pre
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
1.7-rc5
pre
| ||
1.7-rc4
pre
9 CVEs
CVE-2026-35544
GHSA-xpqh-grpw-4xmg
Apr 03, 2026
Roundcube Webmail: Insufficient CSS sanitization in HTML e-mail messages
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to a fixed-position mitigation bypass via the use of !important. Affected versions
1.7-beta
1.7-beta2
1.7-rc
1.7-rc2
1.7-rc3
1.7-rc4
Fixed in
1.7-rc5
References
Updated Apr 04, 2026 · Source: OSV.dev
CVE-2026-35541
GHSA-46pv-mj2g-93gh
Apr 03, 2026
Roundcube Webmail: Incorrect password comparison in the password plugin
4.2
/ 10
Medium
Network
High
Low
None
Unchanged
Low
Low
None
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Incorrect password comparison in the password plugin could lead to type confusion that allows a password change without knowing the old password. Affected versions
1.7-beta
1.7-beta2
1.7-rc
1.7-rc2
1.7-rc3
1.7-rc4
Fixed in
1.7-rc5
References
Updated Apr 04, 2026 · Source: OSV.dev
CVE-2026-35538
GHSA-8jr8-v43g-5c57
Apr 03, 2026
Roundcube Webmail: Unsanitized IMAP SEARCH command arguments
3.1
/ 10
Low
Network
High
Low
None
Unchanged
None
Low
None
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsanitized IMAP SEARCH command arguments could lead to IMAP injection or CSRF bypass during mail search. Affected versions
1.7-beta
1.7-beta2
1.7-rc
1.7-rc2
1.7-rc3
1.7-rc4
Fixed in
1.7-rc5
References
Updated Apr 04, 2026 · Source: OSV.dev
CVE-2026-35543
GHSA-j2g6-8rvg-7mf6
Apr 03, 2026
Roundcube Webmail: Bypass of remote image blocking via SVG content (with animate attributes) in an e-mail message
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via SVG content (with animate attributes) in an e-mail message. This may lead to information disclosure or access-control bypass. Affected versions
1.7-beta
1.7-beta2
1.7-rc
1.7-rc2
1.7-rc3
1.7-rc4
Fixed in
1.7-rc5
References
Updated Apr 04, 2026 · Source: OSV.dev
CVE-2026-35545
GHSA-w846-74jr-76cv
Apr 03, 2026
Roundcube Webmail: Remote image blocking feature can be bypassed via SVG content in an e-mail message
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
An issue was discovered in Roundcube Webmail before 1.5.15 and 1.6.15. The remote image blocking feature can be bypassed via SVG content in an e-mail message. This may lead to information disclosure or access-control bypass. This involves the animate element with attributeName=fill/filter/stroke. Affected versions
1.7-beta
1.7-beta2
1.7-rc
1.7-rc2
1.7-rc3
1.7-rc4
Fixed in
1.7-rc5
References
Updated Apr 04, 2026 · Source: OSV.dev
CVE-2026-35542
GHSA-5hf6-crg4-fg59
Apr 03, 2026
Roundcube: Bypass of remote image blocking via crafted BODY background attribute
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via a crafted background attribute of a BODY element in an e-mail message. This may lead to information disclosure or access-control bypass. Affected versions
1.7-beta
1.7-beta2
1.7-rc
1.7-rc2
1.7-rc3
1.7-rc4
Fixed in
1.7-rc5
References
Updated Apr 04, 2026 · Source: OSV.dev
CVE-2026-35537
GHSA-rxj3-rrwm-pj4r
Apr 03, 2026
Roundcube Webmail: Unsafe deserialization in the redis/memcache session handler
3.7
/ 10
Low
Network
High
None
None
Unchanged
None
Low
None
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsafe deserialization in the redis/memcache session handler may lead to arbitrary file write operations by unauthenticated attackers via crafted session data. Affected versions
1.7-beta
1.7-beta2
1.7-rc
1.7-rc2
1.7-rc3
1.7-rc4
Fixed in
1.7-rc5
References
Updated Apr 14, 2026 · Source: OSV.dev
CVE-2026-35539
GHSA-x4q5-8j5g-hpjc
Apr 03, 2026
Roundcube Webmail: Insufficient HTML attachment sanitization in preview mode
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. XSS exists because of insufficient HTML attachment sanitization in preview mode. A victim must preview a text/html attachment. Affected versions
1.7-beta
1.7-beta2
1.7-rc
1.7-rc2
1.7-rc3
1.7-rc4
Fixed in
1.7-rc5
References
Updated Apr 04, 2026 · Source: OSV.dev
CVE-2026-35540
GHSA-vxg2-hhgr-37fx
Apr 03, 2026
Roundcube Webmail: Insufficient CSS sanitization in HTML e-mail messages
5.4
/ 10
Medium
Network
High
None
None
Changed
Low
Low
None
An issue was discovered in Roundcube Webmail 1.6.0 before 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. Affected versions
1.7-beta
1.7-beta2
1.7-rc
1.7-rc2
1.7-rc3
1.7-rc4
Fixed in
1.7-rc5
References
Updated Apr 04, 2026 · Source: OSV.dev |
1.7-rc4
pre
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
1.7-rc3
pre
9 CVEs
CVE-2026-35544
GHSA-xpqh-grpw-4xmg
Apr 03, 2026
Roundcube Webmail: Insufficient CSS sanitization in HTML e-mail messages
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to a fixed-position mitigation bypass via the use of !important. Affected versions
1.7-beta
1.7-beta2
1.7-rc
1.7-rc2
1.7-rc3
1.7-rc4
Fixed in
1.7-rc5
References
Updated Apr 04, 2026 · Source: OSV.dev
CVE-2026-35541
GHSA-46pv-mj2g-93gh
Apr 03, 2026
Roundcube Webmail: Incorrect password comparison in the password plugin
4.2
/ 10
Medium
Network
High
Low
None
Unchanged
Low
Low
None
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Incorrect password comparison in the password plugin could lead to type confusion that allows a password change without knowing the old password. Affected versions
1.7-beta
1.7-beta2
1.7-rc
1.7-rc2
1.7-rc3
1.7-rc4
Fixed in
1.7-rc5
References
Updated Apr 04, 2026 · Source: OSV.dev
CVE-2026-35538
GHSA-8jr8-v43g-5c57
Apr 03, 2026
Roundcube Webmail: Unsanitized IMAP SEARCH command arguments
3.1
/ 10
Low
Network
High
Low
None
Unchanged
None
Low
None
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsanitized IMAP SEARCH command arguments could lead to IMAP injection or CSRF bypass during mail search. Affected versions
1.7-beta
1.7-beta2
1.7-rc
1.7-rc2
1.7-rc3
1.7-rc4
Fixed in
1.7-rc5
References
Updated Apr 04, 2026 · Source: OSV.dev
CVE-2026-35543
GHSA-j2g6-8rvg-7mf6
Apr 03, 2026
Roundcube Webmail: Bypass of remote image blocking via SVG content (with animate attributes) in an e-mail message
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via SVG content (with animate attributes) in an e-mail message. This may lead to information disclosure or access-control bypass. Affected versions
1.7-beta
1.7-beta2
1.7-rc
1.7-rc2
1.7-rc3
1.7-rc4
Fixed in
1.7-rc5
References
Updated Apr 04, 2026 · Source: OSV.dev
CVE-2026-35545
GHSA-w846-74jr-76cv
Apr 03, 2026
Roundcube Webmail: Remote image blocking feature can be bypassed via SVG content in an e-mail message
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
An issue was discovered in Roundcube Webmail before 1.5.15 and 1.6.15. The remote image blocking feature can be bypassed via SVG content in an e-mail message. This may lead to information disclosure or access-control bypass. This involves the animate element with attributeName=fill/filter/stroke. Affected versions
1.7-beta
1.7-beta2
1.7-rc
1.7-rc2
1.7-rc3
1.7-rc4
Fixed in
1.7-rc5
References
Updated Apr 04, 2026 · Source: OSV.dev
CVE-2026-35542
GHSA-5hf6-crg4-fg59
Apr 03, 2026
Roundcube: Bypass of remote image blocking via crafted BODY background attribute
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via a crafted background attribute of a BODY element in an e-mail message. This may lead to information disclosure or access-control bypass. Affected versions
1.7-beta
1.7-beta2
1.7-rc
1.7-rc2
1.7-rc3
1.7-rc4
Fixed in
1.7-rc5
References
Updated Apr 04, 2026 · Source: OSV.dev
CVE-2026-35537
GHSA-rxj3-rrwm-pj4r
Apr 03, 2026
Roundcube Webmail: Unsafe deserialization in the redis/memcache session handler
3.7
/ 10
Low
Network
High
None
None
Unchanged
None
Low
None
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsafe deserialization in the redis/memcache session handler may lead to arbitrary file write operations by unauthenticated attackers via crafted session data. Affected versions
1.7-beta
1.7-beta2
1.7-rc
1.7-rc2
1.7-rc3
1.7-rc4
Fixed in
1.7-rc5
References
Updated Apr 14, 2026 · Source: OSV.dev
CVE-2026-35539
GHSA-x4q5-8j5g-hpjc
Apr 03, 2026
Roundcube Webmail: Insufficient HTML attachment sanitization in preview mode
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. XSS exists because of insufficient HTML attachment sanitization in preview mode. A victim must preview a text/html attachment. Affected versions
1.7-beta
1.7-beta2
1.7-rc
1.7-rc2
1.7-rc3
1.7-rc4
Fixed in
1.7-rc5
References
Updated Apr 04, 2026 · Source: OSV.dev
CVE-2026-35540
GHSA-vxg2-hhgr-37fx
Apr 03, 2026
Roundcube Webmail: Insufficient CSS sanitization in HTML e-mail messages
5.4
/ 10
Medium
Network
High
None
None
Changed
Low
Low
None
An issue was discovered in Roundcube Webmail 1.6.0 before 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. Affected versions
1.7-beta
1.7-beta2
1.7-rc
1.7-rc2
1.7-rc3
1.7-rc4
Fixed in
1.7-rc5
References
Updated Apr 04, 2026 · Source: OSV.dev | ||
1.7-rc2
pre
9 CVEs
CVE-2026-35544
GHSA-xpqh-grpw-4xmg
Apr 03, 2026
Roundcube Webmail: Insufficient CSS sanitization in HTML e-mail messages
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to a fixed-position mitigation bypass via the use of !important. Affected versions
1.7-beta
1.7-beta2
1.7-rc
1.7-rc2
1.7-rc3
1.7-rc4
Fixed in
1.7-rc5
References
Updated Apr 04, 2026 · Source: OSV.dev
CVE-2026-35541
GHSA-46pv-mj2g-93gh
Apr 03, 2026
Roundcube Webmail: Incorrect password comparison in the password plugin
4.2
/ 10
Medium
Network
High
Low
None
Unchanged
Low
Low
None
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Incorrect password comparison in the password plugin could lead to type confusion that allows a password change without knowing the old password. Affected versions
1.7-beta
1.7-beta2
1.7-rc
1.7-rc2
1.7-rc3
1.7-rc4
Fixed in
1.7-rc5
References
Updated Apr 04, 2026 · Source: OSV.dev
CVE-2026-35538
GHSA-8jr8-v43g-5c57
Apr 03, 2026
Roundcube Webmail: Unsanitized IMAP SEARCH command arguments
3.1
/ 10
Low
Network
High
Low
None
Unchanged
None
Low
None
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsanitized IMAP SEARCH command arguments could lead to IMAP injection or CSRF bypass during mail search. Affected versions
1.7-beta
1.7-beta2
1.7-rc
1.7-rc2
1.7-rc3
1.7-rc4
Fixed in
1.7-rc5
References
Updated Apr 04, 2026 · Source: OSV.dev
CVE-2026-35543
GHSA-j2g6-8rvg-7mf6
Apr 03, 2026
Roundcube Webmail: Bypass of remote image blocking via SVG content (with animate attributes) in an e-mail message
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via SVG content (with animate attributes) in an e-mail message. This may lead to information disclosure or access-control bypass. Affected versions
1.7-beta
1.7-beta2
1.7-rc
1.7-rc2
1.7-rc3
1.7-rc4
Fixed in
1.7-rc5
References
Updated Apr 04, 2026 · Source: OSV.dev
CVE-2026-35545
GHSA-w846-74jr-76cv
Apr 03, 2026
Roundcube Webmail: Remote image blocking feature can be bypassed via SVG content in an e-mail message
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
An issue was discovered in Roundcube Webmail before 1.5.15 and 1.6.15. The remote image blocking feature can be bypassed via SVG content in an e-mail message. This may lead to information disclosure or access-control bypass. This involves the animate element with attributeName=fill/filter/stroke. Affected versions
1.7-beta
1.7-beta2
1.7-rc
1.7-rc2
1.7-rc3
1.7-rc4
Fixed in
1.7-rc5
References
Updated Apr 04, 2026 · Source: OSV.dev
CVE-2026-35542
GHSA-5hf6-crg4-fg59
Apr 03, 2026
Roundcube: Bypass of remote image blocking via crafted BODY background attribute
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via a crafted background attribute of a BODY element in an e-mail message. This may lead to information disclosure or access-control bypass. Affected versions
1.7-beta
1.7-beta2
1.7-rc
1.7-rc2
1.7-rc3
1.7-rc4
Fixed in
1.7-rc5
References
Updated Apr 04, 2026 · Source: OSV.dev
CVE-2026-35537
GHSA-rxj3-rrwm-pj4r
Apr 03, 2026
Roundcube Webmail: Unsafe deserialization in the redis/memcache session handler
3.7
/ 10
Low
Network
High
None
None
Unchanged
None
Low
None
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsafe deserialization in the redis/memcache session handler may lead to arbitrary file write operations by unauthenticated attackers via crafted session data. Affected versions
1.7-beta
1.7-beta2
1.7-rc
1.7-rc2
1.7-rc3
1.7-rc4
Fixed in
1.7-rc5
References
Updated Apr 14, 2026 · Source: OSV.dev
CVE-2026-35539
GHSA-x4q5-8j5g-hpjc
Apr 03, 2026
Roundcube Webmail: Insufficient HTML attachment sanitization in preview mode
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. XSS exists because of insufficient HTML attachment sanitization in preview mode. A victim must preview a text/html attachment. Affected versions
1.7-beta
1.7-beta2
1.7-rc
1.7-rc2
1.7-rc3
1.7-rc4
Fixed in
1.7-rc5
References
Updated Apr 04, 2026 · Source: OSV.dev
CVE-2026-35540
GHSA-vxg2-hhgr-37fx
Apr 03, 2026
Roundcube Webmail: Insufficient CSS sanitization in HTML e-mail messages
5.4
/ 10
Medium
Network
High
None
None
Changed
Low
Low
None
An issue was discovered in Roundcube Webmail 1.6.0 before 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. Affected versions
1.7-beta
1.7-beta2
1.7-rc
1.7-rc2
1.7-rc3
1.7-rc4
Fixed in
1.7-rc5
References
Updated Apr 04, 2026 · Source: OSV.dev | ||
1.7-rc
pre
9 CVEs
CVE-2026-35544
GHSA-xpqh-grpw-4xmg
Apr 03, 2026
Roundcube Webmail: Insufficient CSS sanitization in HTML e-mail messages
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to a fixed-position mitigation bypass via the use of !important. Affected versions
1.7-beta
1.7-beta2
1.7-rc
1.7-rc2
1.7-rc3
1.7-rc4
Fixed in
1.7-rc5
References
Updated Apr 04, 2026 · Source: OSV.dev
CVE-2026-35541
GHSA-46pv-mj2g-93gh
Apr 03, 2026
Roundcube Webmail: Incorrect password comparison in the password plugin
4.2
/ 10
Medium
Network
High
Low
None
Unchanged
Low
Low
None
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Incorrect password comparison in the password plugin could lead to type confusion that allows a password change without knowing the old password. Affected versions
1.7-beta
1.7-beta2
1.7-rc
1.7-rc2
1.7-rc3
1.7-rc4
Fixed in
1.7-rc5
References
Updated Apr 04, 2026 · Source: OSV.dev
CVE-2026-35538
GHSA-8jr8-v43g-5c57
Apr 03, 2026
Roundcube Webmail: Unsanitized IMAP SEARCH command arguments
3.1
/ 10
Low
Network
High
Low
None
Unchanged
None
Low
None
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsanitized IMAP SEARCH command arguments could lead to IMAP injection or CSRF bypass during mail search. Affected versions
1.7-beta
1.7-beta2
1.7-rc
1.7-rc2
1.7-rc3
1.7-rc4
Fixed in
1.7-rc5
References
Updated Apr 04, 2026 · Source: OSV.dev
CVE-2026-35543
GHSA-j2g6-8rvg-7mf6
Apr 03, 2026
Roundcube Webmail: Bypass of remote image blocking via SVG content (with animate attributes) in an e-mail message
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via SVG content (with animate attributes) in an e-mail message. This may lead to information disclosure or access-control bypass. Affected versions
1.7-beta
1.7-beta2
1.7-rc
1.7-rc2
1.7-rc3
1.7-rc4
Fixed in
1.7-rc5
References
Updated Apr 04, 2026 · Source: OSV.dev
CVE-2026-35545
GHSA-w846-74jr-76cv
Apr 03, 2026
Roundcube Webmail: Remote image blocking feature can be bypassed via SVG content in an e-mail message
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
An issue was discovered in Roundcube Webmail before 1.5.15 and 1.6.15. The remote image blocking feature can be bypassed via SVG content in an e-mail message. This may lead to information disclosure or access-control bypass. This involves the animate element with attributeName=fill/filter/stroke. Affected versions
1.7-beta
1.7-beta2
1.7-rc
1.7-rc2
1.7-rc3
1.7-rc4
Fixed in
1.7-rc5
References
Updated Apr 04, 2026 · Source: OSV.dev
CVE-2026-35542
GHSA-5hf6-crg4-fg59
Apr 03, 2026
Roundcube: Bypass of remote image blocking via crafted BODY background attribute
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via a crafted background attribute of a BODY element in an e-mail message. This may lead to information disclosure or access-control bypass. Affected versions
1.7-beta
1.7-beta2
1.7-rc
1.7-rc2
1.7-rc3
1.7-rc4
Fixed in
1.7-rc5
References
Updated Apr 04, 2026 · Source: OSV.dev
CVE-2026-35537
GHSA-rxj3-rrwm-pj4r
Apr 03, 2026
Roundcube Webmail: Unsafe deserialization in the redis/memcache session handler
3.7
/ 10
Low
Network
High
None
None
Unchanged
None
Low
None
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsafe deserialization in the redis/memcache session handler may lead to arbitrary file write operations by unauthenticated attackers via crafted session data. Affected versions
1.7-beta
1.7-beta2
1.7-rc
1.7-rc2
1.7-rc3
1.7-rc4
Fixed in
1.7-rc5
References
Updated Apr 14, 2026 · Source: OSV.dev
CVE-2026-35539
GHSA-x4q5-8j5g-hpjc
Apr 03, 2026
Roundcube Webmail: Insufficient HTML attachment sanitization in preview mode
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. XSS exists because of insufficient HTML attachment sanitization in preview mode. A victim must preview a text/html attachment. Affected versions
1.7-beta
1.7-beta2
1.7-rc
1.7-rc2
1.7-rc3
1.7-rc4
Fixed in
1.7-rc5
References
Updated Apr 04, 2026 · Source: OSV.dev
CVE-2026-35540
GHSA-vxg2-hhgr-37fx
Apr 03, 2026
Roundcube Webmail: Insufficient CSS sanitization in HTML e-mail messages
5.4
/ 10
Medium
Network
High
None
None
Changed
Low
Low
None
An issue was discovered in Roundcube Webmail 1.6.0 before 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. Affected versions
1.7-beta
1.7-beta2
1.7-rc
1.7-rc2
1.7-rc3
1.7-rc4
Fixed in
1.7-rc5
References
Updated Apr 04, 2026 · Source: OSV.dev | ||
1.7-beta2
pre
9 CVEs
CVE-2026-35544
GHSA-xpqh-grpw-4xmg
Apr 03, 2026
Roundcube Webmail: Insufficient CSS sanitization in HTML e-mail messages
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to a fixed-position mitigation bypass via the use of !important. Affected versions
1.7-beta
1.7-beta2
1.7-rc
1.7-rc2
1.7-rc3
1.7-rc4
Fixed in
1.7-rc5
References
Updated Apr 04, 2026 · Source: OSV.dev
CVE-2026-35541
GHSA-46pv-mj2g-93gh
Apr 03, 2026
Roundcube Webmail: Incorrect password comparison in the password plugin
4.2
/ 10
Medium
Network
High
Low
None
Unchanged
Low
Low
None
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Incorrect password comparison in the password plugin could lead to type confusion that allows a password change without knowing the old password. Affected versions
1.7-beta
1.7-beta2
1.7-rc
1.7-rc2
1.7-rc3
1.7-rc4
Fixed in
1.7-rc5
References
Updated Apr 04, 2026 · Source: OSV.dev
CVE-2026-35538
GHSA-8jr8-v43g-5c57
Apr 03, 2026
Roundcube Webmail: Unsanitized IMAP SEARCH command arguments
3.1
/ 10
Low
Network
High
Low
None
Unchanged
None
Low
None
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsanitized IMAP SEARCH command arguments could lead to IMAP injection or CSRF bypass during mail search. Affected versions
1.7-beta
1.7-beta2
1.7-rc
1.7-rc2
1.7-rc3
1.7-rc4
Fixed in
1.7-rc5
References
Updated Apr 04, 2026 · Source: OSV.dev
CVE-2026-35543
GHSA-j2g6-8rvg-7mf6
Apr 03, 2026
Roundcube Webmail: Bypass of remote image blocking via SVG content (with animate attributes) in an e-mail message
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via SVG content (with animate attributes) in an e-mail message. This may lead to information disclosure or access-control bypass. Affected versions
1.7-beta
1.7-beta2
1.7-rc
1.7-rc2
1.7-rc3
1.7-rc4
Fixed in
1.7-rc5
References
Updated Apr 04, 2026 · Source: OSV.dev
CVE-2026-35545
GHSA-w846-74jr-76cv
Apr 03, 2026
Roundcube Webmail: Remote image blocking feature can be bypassed via SVG content in an e-mail message
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
An issue was discovered in Roundcube Webmail before 1.5.15 and 1.6.15. The remote image blocking feature can be bypassed via SVG content in an e-mail message. This may lead to information disclosure or access-control bypass. This involves the animate element with attributeName=fill/filter/stroke. Affected versions
1.7-beta
1.7-beta2
1.7-rc
1.7-rc2
1.7-rc3
1.7-rc4
Fixed in
1.7-rc5
References
Updated Apr 04, 2026 · Source: OSV.dev
CVE-2026-35542
GHSA-5hf6-crg4-fg59
Apr 03, 2026
Roundcube: Bypass of remote image blocking via crafted BODY background attribute
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via a crafted background attribute of a BODY element in an e-mail message. This may lead to information disclosure or access-control bypass. Affected versions
1.7-beta
1.7-beta2
1.7-rc
1.7-rc2
1.7-rc3
1.7-rc4
Fixed in
1.7-rc5
References
Updated Apr 04, 2026 · Source: OSV.dev
CVE-2026-35537
GHSA-rxj3-rrwm-pj4r
Apr 03, 2026
Roundcube Webmail: Unsafe deserialization in the redis/memcache session handler
3.7
/ 10
Low
Network
High
None
None
Unchanged
None
Low
None
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsafe deserialization in the redis/memcache session handler may lead to arbitrary file write operations by unauthenticated attackers via crafted session data. Affected versions
1.7-beta
1.7-beta2
1.7-rc
1.7-rc2
1.7-rc3
1.7-rc4
Fixed in
1.7-rc5
References
Updated Apr 14, 2026 · Source: OSV.dev
CVE-2026-35539
GHSA-x4q5-8j5g-hpjc
Apr 03, 2026
Roundcube Webmail: Insufficient HTML attachment sanitization in preview mode
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. XSS exists because of insufficient HTML attachment sanitization in preview mode. A victim must preview a text/html attachment. Affected versions
1.7-beta
1.7-beta2
1.7-rc
1.7-rc2
1.7-rc3
1.7-rc4
Fixed in
1.7-rc5
References
Updated Apr 04, 2026 · Source: OSV.dev
CVE-2026-35540
GHSA-vxg2-hhgr-37fx
Apr 03, 2026
Roundcube Webmail: Insufficient CSS sanitization in HTML e-mail messages
5.4
/ 10
Medium
Network
High
None
None
Changed
Low
Low
None
An issue was discovered in Roundcube Webmail 1.6.0 before 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. Affected versions
1.7-beta
1.7-beta2
1.7-rc
1.7-rc2
1.7-rc3
1.7-rc4
Fixed in
1.7-rc5
References
Updated Apr 04, 2026 · Source: OSV.dev |
1.7-beta2
pre
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
1.7-beta
pre
9 CVEs
CVE-2026-35544
GHSA-xpqh-grpw-4xmg
Apr 03, 2026
Roundcube Webmail: Insufficient CSS sanitization in HTML e-mail messages
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to a fixed-position mitigation bypass via the use of !important. Affected versions
1.7-beta
1.7-beta2
1.7-rc
1.7-rc2
1.7-rc3
1.7-rc4
Fixed in
1.7-rc5
References
Updated Apr 04, 2026 · Source: OSV.dev
CVE-2026-35541
GHSA-46pv-mj2g-93gh
Apr 03, 2026
Roundcube Webmail: Incorrect password comparison in the password plugin
4.2
/ 10
Medium
Network
High
Low
None
Unchanged
Low
Low
None
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Incorrect password comparison in the password plugin could lead to type confusion that allows a password change without knowing the old password. Affected versions
1.7-beta
1.7-beta2
1.7-rc
1.7-rc2
1.7-rc3
1.7-rc4
Fixed in
1.7-rc5
References
Updated Apr 04, 2026 · Source: OSV.dev
CVE-2026-35538
GHSA-8jr8-v43g-5c57
Apr 03, 2026
Roundcube Webmail: Unsanitized IMAP SEARCH command arguments
3.1
/ 10
Low
Network
High
Low
None
Unchanged
None
Low
None
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsanitized IMAP SEARCH command arguments could lead to IMAP injection or CSRF bypass during mail search. Affected versions
1.7-beta
1.7-beta2
1.7-rc
1.7-rc2
1.7-rc3
1.7-rc4
Fixed in
1.7-rc5
References
Updated Apr 04, 2026 · Source: OSV.dev
CVE-2026-35543
GHSA-j2g6-8rvg-7mf6
Apr 03, 2026
Roundcube Webmail: Bypass of remote image blocking via SVG content (with animate attributes) in an e-mail message
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via SVG content (with animate attributes) in an e-mail message. This may lead to information disclosure or access-control bypass. Affected versions
1.7-beta
1.7-beta2
1.7-rc
1.7-rc2
1.7-rc3
1.7-rc4
Fixed in
1.7-rc5
References
Updated Apr 04, 2026 · Source: OSV.dev
CVE-2026-35545
GHSA-w846-74jr-76cv
Apr 03, 2026
Roundcube Webmail: Remote image blocking feature can be bypassed via SVG content in an e-mail message
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
An issue was discovered in Roundcube Webmail before 1.5.15 and 1.6.15. The remote image blocking feature can be bypassed via SVG content in an e-mail message. This may lead to information disclosure or access-control bypass. This involves the animate element with attributeName=fill/filter/stroke. Affected versions
1.7-beta
1.7-beta2
1.7-rc
1.7-rc2
1.7-rc3
1.7-rc4
Fixed in
1.7-rc5
References
Updated Apr 04, 2026 · Source: OSV.dev
CVE-2026-35542
GHSA-5hf6-crg4-fg59
Apr 03, 2026
Roundcube: Bypass of remote image blocking via crafted BODY background attribute
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via a crafted background attribute of a BODY element in an e-mail message. This may lead to information disclosure or access-control bypass. Affected versions
1.7-beta
1.7-beta2
1.7-rc
1.7-rc2
1.7-rc3
1.7-rc4
Fixed in
1.7-rc5
References
Updated Apr 04, 2026 · Source: OSV.dev
CVE-2026-35537
GHSA-rxj3-rrwm-pj4r
Apr 03, 2026
Roundcube Webmail: Unsafe deserialization in the redis/memcache session handler
3.7
/ 10
Low
Network
High
None
None
Unchanged
None
Low
None
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsafe deserialization in the redis/memcache session handler may lead to arbitrary file write operations by unauthenticated attackers via crafted session data. Affected versions
1.7-beta
1.7-beta2
1.7-rc
1.7-rc2
1.7-rc3
1.7-rc4
Fixed in
1.7-rc5
References
Updated Apr 14, 2026 · Source: OSV.dev
CVE-2026-35539
GHSA-x4q5-8j5g-hpjc
Apr 03, 2026
Roundcube Webmail: Insufficient HTML attachment sanitization in preview mode
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. XSS exists because of insufficient HTML attachment sanitization in preview mode. A victim must preview a text/html attachment. Affected versions
1.7-beta
1.7-beta2
1.7-rc
1.7-rc2
1.7-rc3
1.7-rc4
Fixed in
1.7-rc5
References
Updated Apr 04, 2026 · Source: OSV.dev
CVE-2026-35540
GHSA-vxg2-hhgr-37fx
Apr 03, 2026
Roundcube Webmail: Insufficient CSS sanitization in HTML e-mail messages
5.4
/ 10
Medium
Network
High
None
None
Changed
Low
Low
None
An issue was discovered in Roundcube Webmail 1.6.0 before 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. Affected versions
1.7-beta
1.7-beta2
1.7-rc
1.7-rc2
1.7-rc3
1.7-rc4
Fixed in
1.7-rc5
References
Updated Apr 04, 2026 · Source: OSV.dev |