FAIL › dossier
Roundcube Webmail
PRODUCT· dossier confidence 50%
Roundcube Webmail faces significant security risks due to multiple high-severity vulnerabilities, including remote code execution flaws.
PROFILE
CategorySoftwareWhat they doRoundcube Webmail is an open-source web-based email client.
SECURITY POSTURE
High risk due to multiple high severity vulnerabilities
Notable failures
- CVE-2021-44026
- CVE-2020-12641
- CVE-2020-35730
- CVE-2017-16651
Patterns: repeated unpatched edge-device RCEs
FAILURE HISTORY · 4
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2023-06-22 | CVE-2021-44026 | high | Roundcube Webmail SQL Injection Vulnerability exposed in over 84,000 servers. |
| 2023-06-22 | CVE-2020-12641 | high | Roundcube Webmail Remote Code Execution Vulnerability exposed in 84,000 servers |
| 2023-06-22 | CVE-2020-35730 | high | Roundcube Webmail XSS vulnerability exposed in 84,000 servers |
| 2021-11-03 | CVE-2017-16651 | high | Roundcube Webmail's default file-based attachment plugins suffered a file disclosure vulnerability due to insufficient input validation, exposing sensitive data on over 84,000 servers. |
Open questions: What is the current status of these vulnerabilities? · Are there any patches available for these vulnerabilities?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-05 03:44:11.863663+00:00