Brand
Roundcube: actively exploited vulnerabilities
11 vulnerabilities in Roundcube products (Webmail) are in CISA’s catalog of exploited vulnerabilities. Last added: February 20, 2026.
The brand’s general security advisories page, not the advisory for a specific vulnerability (address checked September 28, 2026).
-
2 vulnerabilities added in the last 12 months
-
11 exploited vulnerabilities in the catalog, in total
-
0 added in the last 30 days
By category
Add just one Roundcube category to your radar, or open its page.
- Email 11 vulnerabilities
A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.
Affected products
- Webmail 11 vulnerabilities · Email
Name used by CISA: Roundcube. Product families: indicative classification by this site.
Patch first
In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this Roundcube list.
Rank 1Roundcube Webmail
CVE-2025-49113RoundCube Webmail Deserialization of Untrusted Data Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Feb 20, 2026
- CISA deadline
- 21 days
- CVSS severity
- 8.8 (high)
Rank 2Roundcube Webmail
CVE-2025-68461RoundCube Webmail Cross-site Scripting Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Feb 20, 2026
- CISA deadline
- 21 days
- CVSS severity
- 6.1 (medium)
Rank 3Roundcube Webmail
CVE-2020-12641CVE from 2020, added in 2023
Roundcube Webmail Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jun 22, 2023
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 4Roundcube Webmail
CVE-2021-44026CVE from 2021, added in 2023
Roundcube Webmail SQL Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jun 22, 2023
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 5Roundcube Webmail
CVE-2024-42009RoundCube Webmail Cross-Site Scripting Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jun 9, 2025
- CISA deadline
- 21 days
- CVSS severity
- 9.3 (critical)
Rank 6Roundcube Webmail
CVE-2017-16651CVE from 2017, added in 2021
Roundcube Webmail File Disclosure Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 7.8 (high)
Rank 7Roundcube Webmail
CVE-2024-37383RoundCube Webmail Cross-Site Scripting (XSS) Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Oct 24, 2024
- CISA deadline
- 21 days
- CVSS severity
- 6.1 (medium)
Rank 8Roundcube Webmail
CVE-2020-13965CVE from 2020, added in 2024
Roundcube Webmail Cross-Site Scripting (XSS) Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jun 26, 2024
- CISA deadline
- 21 days
- CVSS severity
- 6.1 (medium)
Rank 9Roundcube Webmail
CVE-2023-43770Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Feb 12, 2024
- CISA deadline
- 21 days
- CVSS severity
- 6.1 (medium)
Rank 10Roundcube Webmail
CVE-2020-35730CVE from 2020, added in 2023
Roundcube Webmail Cross-Site Scripting (XSS) Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jun 22, 2023
- CISA deadline
- 21 days
- CVSS severity
- 6.1 (medium)
Show 1 more vulnerability
Rank 11Roundcube Webmail
CVE-2023-5631Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Oct 26, 2023
- CISA deadline
- 21 days
- CVSS severity
- 5.4 (medium)
Follow and verify
Get new Roundcube vulnerabilities: RSS feed (add it to Outlook, Teams, Slack or your feed reader).
Indicative classification, based on the vendor and product names given by CISA. How products are classified.