50 exploited vulnerabilities in Roundcube Webmail
- Vendors
- Unknown, Alt Linux, Linux Mint, Suse, Canonical, Atmail
- With known exploits
- 50
- Affected Roundcube Webmail versions
- < 1.6.17, 1.7.2, 0.2.1, 0.2.3, 1.5.10, 1.6.11, 1.2.10, 1.3.11, 1.4.4, 1.5.8, 1.6.8, 1.5.15, 1.6.15, 1.1.9, 1.2.0, 1.2.1, 1.2.2, 1.2.3, 1.2.4, 1.2.5, 1.2.6, 1.3.0, 1.3.1, 1.3.2, 1.5.12, 1.6.12, 1.5.7, 1.6.7, 1.3.12, 1.4.5, 1.2.13, 1.3.16, 1.4.10, 1.5.13, 1.6.13, 1.5.14, 1.6.14
- Affected Iredmail versions
- β€ 0.9.6
Vulnerabilities with exploits
Highest CVSS first β 14 of these already have exploit code on Sploitus
CVE-2026-54433
CVE-2020-12641
CVE-2008-5619 14 exploits
RoundCube Webmail <= 0.2-3 beta Code Execution VulnerabilityRoundCube Webmail <= 0.2b Remote Code Execution Exploit
CVE-2025-49113 28 exploits
Exploit for Deserialization of Untrusted Data in Roundcube WebmailExploit for Deserialization of Untrusted Data in Roundcube Webmail
CVE-2024-37385
CVE-2020-12640
CVE-2024-42009 6 exploits
Exploit for Cross-site Scripting in Roundcube WebmailExploit for Cross-site Scripting in Roundcube Webmail
CVE-2017-8114
CVE-2026-35545
CVE-2026-48842
CVE-2026-35537
CVE-2017-16651 4 exploits
CVE-2026-48844
CVE-2025-68460
CVE-2018-1000072
CVE-2026-48848
CVE-2026-48843
CVE-2025-68461 1 exploit
CVE-2020-12626
CVE-2026-48846
CVE-2026-48845
CVE-2026-35540
CVE-2026-35539
CVE-2024-37383 5 exploits
Roundcube Webmail 1.6.6 - Stored Cross Site Scripting (XSS)π Roundcube 1.6.6 Cross Site Scripting
CVE-2020-13965 1 exploit
CVE-2024-57004
CVE-2024-37384
CVE-2020-35730 1 exploit
CVE-2020-16145
CVE-2020-12625
CVE-2020-13964
CVE-2020-15562
CVE-2016-4552
CVE-2026-35544
CVE-2026-35543
CVE-2026-35542
CVE-2026-26079
CVE-2026-25916 2 exploits
CVE-2026-48849 1 exploit
CVE-2019-10740
CVE-2013-5645 1 exploit
CVE-2012-4668 1 exploit
CVE-2012-3508 1 exploit
CVE-2011-2937
CVE-2007-6321 1 exploit
CVE-2026-35541
CVE-2026-48847
CVE-2013-5646
CVE-2026-35538
CVE-2012-3507