PROFILE
CategoryVendorWhat they doRoundcube is an open-source webmail client that provides a modern interface for managing email accounts.
Websitehttps://… ↗
SECURITY POSTURE
Roundcube has been identified with multiple vulnerabilities that have been actively exploited in the wild.
Notable failures
- CVE-2025-49113 (high [RCE])
- CVE-2025-68461 (high [RCE])
- CVE-2020-12641 (high [RCE])
- CVE-2024-42009 (high)
- CVE-2024-37383 (high)
- CVE-2024-13965 (high)
- CVE-2024-23770 (high)
- CVE-2023-5631 (high)
- CVE-2023-43770 (high)
- CVE-2023-5631 (high)
- CVE-2021-16651 (high)
- CVE-2026-54433 (high)
- CVE-2026-62643 (high)
- CVE-2026-62644 (medium)
Patterns: Repeated unpatched remote code execution vulnerabilities; Persistent cross-site scripting vulnerabilities leading to information disclosure; Cross-site scripting vulnerabilities allowing for malicious payload execution
FAILURE HISTORY · 14
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2026-02-20 | CVE-2025-68461 | high | Over 84,000 Roundcube Webmail servers remain unpatched for a critical XSS flaw, actively exploited in the wild |
| 2026-02-20 | CVE-2025-49113 | high | Over 84,000 Roundcube Webmail servers remain unpatched for a remote code execution flaw |
| 2025-06-09 | CVE-2024-42009 | high | Over 84,000 Roundcube Webmail servers actively exploited for XSS |
| 2023-10-26 | CVE-2023-5631 | high | Roundcube Webmail XSS vulnerability exposed in 84,000 servers |
| 2023-06-22 | CVE-2021-44026 | high | Roundcube Webmail SQL Injection Vulnerability exposed in over 84,000 servers. |
| 2023-06-22 | CVE-2020-12641 | high | Roundcube Webmail Remote Code Execution Vulnerability exposed in 84,000 servers |
| 2023-06-22 | CVE-2020-35730 | high | Roundcube Webmail XSS vulnerability exposed in 84,000 servers |
| 2021-11-03 | CVE-2017-16651 | high | Roundcube Webmail's default file-based attachment plugins suffered a file disclosure vulnerability due to insufficient input validation, exposing sensitive data on over 84,000 servers. |
| 2024-10-24 | CVE-2024-37383 | high | RoundCube Webmail exploited a remote XSS flaw in SVG animate attributes affecting over 84,000 servers. |
| 2024-02-12 | CVE-2023-43770 | high | Roundcube Webmail servers are actively exploited via a persistent XSS vulnerability that enables remote code execution. |
| 2024-06-26 | CVE-2020-13965 | high | Roundcube Webmail exploited via CVE-2020-13965 allows remote attackers to execute arbitrary code through malicious XML attachments. |
| 2026-07-14 | CVE-2026-62643 | high | CVE-2026-62643: In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascadin |
| 2026-07-14 | CVE-2026-62644 | medium | CVE-2026-62644: In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin o |
| 2026-07-14 | CVE-2026-54433 | high | CVE-2026-54433: In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross |
SENTIMENT · TRUSTED SOURCES
synthesissevere-fallout-0.60
Vulnerability in default plugins caused file disclosure, indicating poor default security posture.
Vulnerability in default plugins caused file disclosure, indicating poor default security posture.
"Roundcube Webmail contains a file disclosure vulnerability caused by insufficient input validation in conjunction with file-based attachment plugins, which are used by default."
DOSSIER SOURCES
- Roundcube Webmail Vulnerability Exploited in Real-World Attacks · blog.gridinsoft.com
- [SECURITY] [DSA 6391-1] roundcube security update · lists.debian.org
- Debian DLA-4693-1 Roundcube Security Update for Multiple Issues · linuxsecurity.com
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-24 03:44:08.378933+00:00