VENDOR
Roundcube vulnerabilities: CVEs, exploitation and patches
Every Roundcube CVE reviewed by Diras Labs analysts, newest first, with exploitation status and fixes.
-
CVE-2026-75003
Roundcube Webmail SVG url() bypass lets crafted images leak dataCRITICAL 9.8
- PATCH AVAILABLE
- CVE-2026-62643 CRITICAL 10
-
CVE-2026-54433
Roundcube Webmail stored XSS zero-click via crafted emailCRITICAL 10
- PoC PUBLIC
- PATCH AVAILABLE
No CVEs on this page match the filters.
3 CVEs · page 1 of 1