CVE security advisories and vulnerability history for roundcubemail by roundcube.
43
Total CVEs
Published
11
In CISA KEV
Exploited in the wild
12
Public exploits
With known exploit
7.3
Avg CVSS
2016–2026
Last updated
Overview
roundcube roundcubemail has 43 published CVE records since 2016, of which 11 are in CISA's Known Exploited Vulnerabilities catalog and 12 have a known public exploit. The average CVSS base score across scored CVEs is 7.3.
This page aggregates every publicly disclosed vulnerability (CVE) affecting roundcube roundcubemail, with a severity breakdown, the affected and patched versions, the most common weakness types, and the full CVE list.
Severity and exploitation
How the CVSS severity of roundcube roundcubemail's CVEs breaks down, plus how many are exploited in the wild or have public exploit code.
Critical5
High5
Medium10
Low0
23 additional CVEs have no CVSS severity score.
In CISA’s Known Exploited Vulnerabilities catalog
11
11 of roundcube roundcubemail's CVEs are confirmed exploited in the wild.
Public exploits
12
12 of roundcube roundcubemail's CVEs have a known public exploit available.
Affected versions and CVEs
Browse every roundcube roundcubemail version named in a CVE, then pick one to see only the CVEs that affect it.
Common questions about roundcube roundcubemail vulnerabilities.
How many CVEs does roundcube roundcubemail have?
roundcube roundcubemail has 43 published CVE records since 2016.
How many roundcube roundcubemail CVEs are in CISA KEV?
Yes — 11 of roundcube roundcubemail's CVEs are listed in CISA's Known Exploited Vulnerabilities catalog, confirmed exploited in the wild and carrying a CISA remediation deadline.
Are there public exploits for roundcube roundcubemail vulnerabilities?
Yes — 12 of roundcube roundcubemail's CVEs have a known public exploit.
Which versions of roundcube roundcubemail are affected?
181 distinct roundcube roundcubemail versions are named across its CVEs. Use the version filter above to see the CVEs affecting a specific version.
What are the most common weakness types in roundcube roundcubemail CVEs?
roundcube roundcubemail's CVEs most often map to these CWE weakness types: CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')), CWE-80 (Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)), CWE-420 (Unprotected Alternate Channel), CWE-502 (Deserialization of Untrusted Data).
How many critical roundcube roundcubemail vulnerabilities are there?
roundcube roundcubemail has 5 critical and 5 high-severity CVEs.
What is the average severity of roundcube roundcubemail CVEs?
The average CVSS base score across roundcube roundcubemail's scored CVEs is 7.3.