Skip to content
COOEY

FAIL › dossier

Roundcube Webmail

PRODUCT

· dossier confidence 50%

Roundcube Webmail faces significant security risks due to multiple high-severity vulnerabilities, including remote code execution flaws.

PROFILE
CategorySoftwareWhat they doRoundcube Webmail is an open-source web-based email client.
SECURITY POSTURE

High risk due to multiple high severity vulnerabilities

Notable failures
  • CVE-2021-44026
  • CVE-2020-12641
  • CVE-2020-35730
  • CVE-2017-16651
Patterns: repeated unpatched edge-device RCEs
FAILURE HISTORY · 4
DATEEVENTSEVSUMMARY
2023-06-22 CVE-2021-44026 high Roundcube Webmail SQL Injection Vulnerability exposed in over 84,000 servers.
2023-06-22 CVE-2020-12641 high Roundcube Webmail Remote Code Execution Vulnerability exposed in 84,000 servers
2023-06-22 CVE-2020-35730 high Roundcube Webmail XSS vulnerability exposed in 84,000 servers
2021-11-03 CVE-2017-16651 high Roundcube Webmail's default file-based attachment plugins suffered a file disclosure vulnerability due to insufficient input validation, exposing sensitive data on over 84,000 servers.
Open questions: What is the current status of these vulnerabilities? · Are there any patches available for these vulnerabilities?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-05 03:44:11.863663+00:00