PROFILE
CategoryWebmailWhat they doRoundcube Webmail is an open-source webmail application that provides a modern interface for managing email, contacts, and calendar events.
SECURITY POSTURE
The company has been repeatedly affected by high-severity vulnerabilities in Roundcube Webmail, indicating a potential lack of robust security practices.
Notable failures
- CVE-2025-49113: High [RCE] - Over 84,000 servers remain unpatched
- CVE-2025-68461: High [RCE] - Over 84,000 servers actively exploited
- CVE-2024-42009: High [RCE] - Over 84,000 servers actively exploited
- CVE-2024-37383: High - XSS vulnerability in SVG handling
- CVE-2020-13965: High - XSS vulnerability via malicious XML attachment
- CVE-2023-43770: High - Persistent XSS vulnerability in plain/text messages
- CVE-2023-5631: High - Persistent XSS vulnerability
- CVE-2026-54433: High - Stored Cross
- CVE-2026-62643: High - Insufficient Cascadin
- CVE-2026-62644: Medium - Password plugin
Patterns: Repeated unpatched high-severity vulnerabilities in Roundcube Webmail; Persistent XSS vulnerabilities leading to potential remote code execution
FAILURE HISTORY · 10
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2026-02-20 | CVE-2025-49113 | high | Over 84,000 Roundcube Webmail servers remain unpatched for a remote code execution flaw |
| 2026-02-20 | CVE-2025-68461 | high | Over 84,000 Roundcube Webmail servers remain unpatched for a critical XSS flaw, actively exploited in the wild |
| 2025-06-09 | CVE-2024-42009 | high | Over 84,000 Roundcube Webmail servers actively exploited for XSS |
| 2023-10-26 | CVE-2023-5631 | high | Roundcube Webmail XSS vulnerability exposed in 84,000 servers |
| 2024-10-24 | CVE-2024-37383 | high | RoundCube Webmail exploited a remote XSS flaw in SVG animate attributes affecting over 84,000 servers. |
| 2024-02-12 | CVE-2023-43770 | high | Roundcube Webmail servers are actively exploited via a persistent XSS vulnerability that enables remote code execution. |
| 2024-06-26 | CVE-2020-13965 | high | Roundcube Webmail exploited via CVE-2020-13965 allows remote attackers to execute arbitrary code through malicious XML attachments. |
| 2026-07-14 | CVE-2026-54433 | high | CVE-2026-54433: In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross |
| 2026-07-14 | CVE-2026-62643 | high | CVE-2026-62643: In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascadin |
| 2026-07-14 | CVE-2026-62644 | medium | CVE-2026-62644: In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin o |
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-27 03:41:38.892414+00:00