Roundcube Vulnerabilities
Roundcube Webmail is a free, open-source, browser-based IMAP email client. The database tracks 11 Roundcube CVE records. CISA lists 11 of them as exploited in the wild, most recently on 2026-02-20. The most affected products are Webmail, Roundcube Webmail.
Recently Exploited Roundcube CVEs
RoundCube Webmail Deserialization of Untrusted Data Vulnerability
RoundCube Webmail Cross-site Scripting Vulnerability
RoundCube Webmail Cross-Site Scripting Vulnerability
RoundCube Webmail Cross-Site Scripting (XSS) Vulnerability
Roundcube Webmail Cross-Site Scripting (XSS) Vulnerability
Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability
Affected Products
2 products| Product | CVEs | KEV | Latest |
|---|---|---|---|
| Webmail | 7 | 7 | 2026-02-20 |
| Roundcube Webmail | 4 | 4 | 2023-06-22 |
Security Advisories
Weakness Types
All Roundcube CVEs
11 records| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2025-49113 | RoundCube Webmail Deserialization of Untrusted Data Vulnerability | Roundcube | 9.9 | 99.0% | KEV | 2025-06-02 |
| CVE-2025-68461 | RoundCube Webmail Cross-site Scripting Vulnerability | Roundcube | 7.2 | 26.8% | KEV | 2025-12-18 |
| CVE-2024-42009 | RoundCube Webmail Cross-Site Scripting Vulnerability | - | 9.3 | 82.9% | KEV | 2024-08-05 |
| CVE-2024-37383 | RoundCube Webmail Cross-Site Scripting (XSS) Vulnerability | - | 6.1 | 73.3% | KEV | 2024-06-07 |
| CVE-2020-13965 | Roundcube Webmail Cross-Site Scripting (XSS) Vulnerability | - | 6.3 | 76.6% | KEV | 2020-06-09 |
| CVE-2023-43770 | Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability | - | 6.1 | 63.7% | KEV | 2023-09-22 |
| CVE-2023-5631 | Stored XSS vulnerability in Roundcube | Roundcube | 6.1 | 75.9% | KEV | 2023-10-18 |
| CVE-2020-12641 | Roundcube Webmail Remote Code Execution Vulnerability | - | 9.8 | 84.3% | KEV | 2020-05-04 |
| CVE-2021-44026 | Roundcube Webmail SQL Injection Vulnerability | - | 9.8 | 69.9% | KEV | 2021-11-19 |
| CVE-2020-35730 | Roundcube Webmail Cross-Site Scripting (XSS) Vulnerability | - | 6.1 | 32.9% | KEV | 2020-12-28 |
| CVE-2017-16651 | Roundcube Webmail File Disclosure Vulnerability | - | 7.8 | 45.7% | KEV | 2017-11-09 |
Frequently Asked Questions
How many Roundcube vulnerabilities are actively exploited?→
11 Roundcube CVEs are in the CISA Known Exploited Vulnerabilities catalog as of 2026-10-09. The latest was added on 2026-02-20.
Which Roundcube products have the most exploited vulnerabilities?→
- +Webmail: 7 CVEs (7 in KEV)
- +Roundcube Webmail: 4 CVEs (4 in KEV)
Where does Roundcube publish security advisories?→
Roundcube publishes security advisories at https://github.com/roundcube/roundcubemail/security/advisories. Check the vendor advisory for fixed versions and workarounds before applying updates.
Sources
CVE record data © The MITRE Corporation, used under the CVE Terms of Use. Vendor and product names for exploited CVEs follow the CISA Known Exploited Vulnerabilities catalog (CC0). Exploit prediction scores by FIRST EPSS (first.org/epss). This site is not affiliated with or endorsed by Roundcube, MITRE, CISA, or FIRST.