Fixed Intel

CVE Tracker

Track known exploited vulnerabilities, CISA KEV alerts, and linked threat intelligence.

1,542

Total CVEs

1,542

CISA KEV

35

Known Exploits

9.3

Avg CVSS Score

Severity Distribution

HIGH 1542

Showing 11 of 11 CVEs matching "Roundcube" · CISA KEV

CVE-2025-49113KEV
High

RoundCube Webmail contains a deserialization of untrusted data vulnerability that allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php.

RoundcubeEPSS 90.4%
CVE-2025-68461KEV
High

RoundCube Webmail contains a cross-site scripting vulnerability via the animate tag in an SVG document.

RoundcubeEPSS 6.3%
CVE-2024-42009KEV
High

RoundCube Webmail contains a cross-site scripting vulnerability. This vulnerability could allow a remote attacker to steal and send emails of a victim via a crafted e-mail message that abuses a Desanitization issue in message_body() in program/actions/mail/show.php.

RoundcubeEPSS 91.2%
CVE-2024-37383KEV
High

RoundCube Webmail contains a cross-site scripting (XSS) vulnerability in the handling of SVG animate attributes that allows a remote attacker to run malicious JavaScript code.

RoundcubeEPSS 64.0%
CVE-2020-13965KEV
High

Roundcube Webmail contains a cross-site scripting (XSS) vulnerability that allows a remote attacker to manipulate data via a malicious XML attachment.

RoundcubeEPSS 82.7%
CVE-2023-43770KEV
High

Roundcube Webmail contains a persistent cross-site scripting (XSS) vulnerability that can lead to information disclosure via malicious link references in plain/text messages.

RoundcubeEPSS 77.1%
CVE-2023-5631KEV
High

Roundcube Webmail contains a persistent cross-site scripting (XSS) vulnerability that allows a remote attacker to run malicious JavaScript code.

RoundcubeEPSS 83.4%
CVE-2021-44026KEV
High

Roundcube Webmail is vulnerable to SQL injection via search or search_params.

RoundcubeEPSS 64.0%
CVE-2020-35730KEV
High

Roundcube Webmail contains a cross-site scripting (XSS) vulnerability that allows an attacker to send a plain text e-mail message with Javascript in a link reference element that is mishandled by linkref_addinindex in rcube_string_replacer.php.

RoundcubeEPSS 64.8%
CVE-2020-12641KEV
High

Roundcube Webmail contains an remote code execution vulnerability that allows attackers to execute code via shell metacharacters in a configuration setting for im_convert_path or im_identify_path.

RoundcubeEPSS 93.1%
CVE-2017-16651KEV
High

Roundcube Webmail contains a file disclosure vulnerability caused by insufficient input validation in conjunction with file-based attachment plugins, which are used by default.

RoundcubeEPSS 37.8%