Skip to content
COOEY

FAIL › dossier

Roundcube

VENDOR

· dossier confidence 20%

PROFILE
CategoryVendorWhat they doRoundcube is an open-source webmail client that provides a modern interface for managing email accounts. Websitehttps://… ↗
SECURITY POSTURE

Roundcube has been identified with multiple vulnerabilities that have been actively exploited in the wild.

Notable failures
  • CVE-2025-49113 (high [RCE])
  • CVE-2025-68461 (high [RCE])
  • CVE-2020-12641 (high [RCE])
  • CVE-2024-42009 (high)
  • CVE-2024-37383 (high)
  • CVE-2024-13965 (high)
  • CVE-2024-23770 (high)
  • CVE-2023-5631 (high)
  • CVE-2023-43770 (high)
  • CVE-2023-5631 (high)
  • CVE-2021-16651 (high)
  • CVE-2026-54433 (high)
  • CVE-2026-62643 (high)
  • CVE-2026-62644 (medium)
Patterns: Repeated unpatched remote code execution vulnerabilities; Persistent cross-site scripting vulnerabilities leading to information disclosure; Cross-site scripting vulnerabilities allowing for malicious payload execution
FAILURE HISTORY · 14
DATEEVENTSEVSUMMARY
2026-02-20 CVE-2025-68461 high Over 84,000 Roundcube Webmail servers remain unpatched for a critical XSS flaw, actively exploited in the wild
2026-02-20 CVE-2025-49113 high Over 84,000 Roundcube Webmail servers remain unpatched for a remote code execution flaw
2025-06-09 CVE-2024-42009 high Over 84,000 Roundcube Webmail servers actively exploited for XSS
2023-10-26 CVE-2023-5631 high Roundcube Webmail XSS vulnerability exposed in 84,000 servers
2023-06-22 CVE-2021-44026 high Roundcube Webmail SQL Injection Vulnerability exposed in over 84,000 servers.
2023-06-22 CVE-2020-12641 high Roundcube Webmail Remote Code Execution Vulnerability exposed in 84,000 servers
2023-06-22 CVE-2020-35730 high Roundcube Webmail XSS vulnerability exposed in 84,000 servers
2021-11-03 CVE-2017-16651 high Roundcube Webmail's default file-based attachment plugins suffered a file disclosure vulnerability due to insufficient input validation, exposing sensitive data on over 84,000 servers.
2024-10-24 CVE-2024-37383 high RoundCube Webmail exploited a remote XSS flaw in SVG animate attributes affecting over 84,000 servers.
2024-02-12 CVE-2023-43770 high Roundcube Webmail servers are actively exploited via a persistent XSS vulnerability that enables remote code execution.
2024-06-26 CVE-2020-13965 high Roundcube Webmail exploited via CVE-2020-13965 allows remote attackers to execute arbitrary code through malicious XML attachments.
2026-07-14 CVE-2026-62643 high CVE-2026-62643: In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascadin
2026-07-14 CVE-2026-62644 medium CVE-2026-62644: In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin o
2026-07-14 CVE-2026-54433 high CVE-2026-54433: In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross
SENTIMENT · TRUSTED SOURCES
synthesissevere-fallout-0.60
Vulnerability in default plugins caused file disclosure, indicating poor default security posture.
cooey ↗severe-fallout-0.60
Vulnerability in default plugins caused file disclosure, indicating poor default security posture.
"Roundcube Webmail contains a file disclosure vulnerability caused by insufficient input validation in conjunction with file-based attachment plugins, which are used by default."
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-24 03:44:08.378933+00:00