Skip to content
COOEY

FAIL › dossier

Webmail

PRODUCT

· dossier confidence 50%

PROFILE
CategoryWebmailWhat they doRoundcube Webmail is an open-source webmail application that provides a modern interface for managing email, contacts, and calendar events.
SECURITY POSTURE

The company has been repeatedly affected by high-severity vulnerabilities in Roundcube Webmail, indicating a potential lack of robust security practices.

Notable failures
  • CVE-2025-49113: High [RCE] - Over 84,000 servers remain unpatched
  • CVE-2025-68461: High [RCE] - Over 84,000 servers actively exploited
  • CVE-2024-42009: High [RCE] - Over 84,000 servers actively exploited
  • CVE-2024-37383: High - XSS vulnerability in SVG handling
  • CVE-2020-13965: High - XSS vulnerability via malicious XML attachment
  • CVE-2023-43770: High - Persistent XSS vulnerability in plain/text messages
  • CVE-2023-5631: High - Persistent XSS vulnerability
  • CVE-2026-54433: High - Stored Cross
  • CVE-2026-62643: High - Insufficient Cascadin
  • CVE-2026-62644: Medium - Password plugin
Patterns: Repeated unpatched high-severity vulnerabilities in Roundcube Webmail; Persistent XSS vulnerabilities leading to potential remote code execution
FAILURE HISTORY · 10
DATEEVENTSEVSUMMARY
2026-02-20 CVE-2025-49113 high Over 84,000 Roundcube Webmail servers remain unpatched for a remote code execution flaw
2026-02-20 CVE-2025-68461 high Over 84,000 Roundcube Webmail servers remain unpatched for a critical XSS flaw, actively exploited in the wild
2025-06-09 CVE-2024-42009 high Over 84,000 Roundcube Webmail servers actively exploited for XSS
2023-10-26 CVE-2023-5631 high Roundcube Webmail XSS vulnerability exposed in 84,000 servers
2024-10-24 CVE-2024-37383 high RoundCube Webmail exploited a remote XSS flaw in SVG animate attributes affecting over 84,000 servers.
2024-02-12 CVE-2023-43770 high Roundcube Webmail servers are actively exploited via a persistent XSS vulnerability that enables remote code execution.
2024-06-26 CVE-2020-13965 high Roundcube Webmail exploited via CVE-2020-13965 allows remote attackers to execute arbitrary code through malicious XML attachments.
2026-07-14 CVE-2026-54433 high CVE-2026-54433: In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross
2026-07-14 CVE-2026-62643 high CVE-2026-62643: In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascadin
2026-07-14 CVE-2026-62644 medium CVE-2026-62644: In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin o
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-27 03:41:38.892414+00:00