Vuln
·
Scope
首頁
套件
KEV
Critical
深度報告
EN
中
Loading…
Packagist/roundcube/roundcubemail — 10 CVEs · VulnScope
pkg:Packagist/
roundcube/roundcubemail
共 10 筆 CVE
CRITICAL
1
MEDIUM
7
LOW
2
✅ 檢查你的版本
檢查
所有已知漏洞
CRITICAL
9.9
CVE-2025-49113
⚠ KEV
roundcube - security update
from 0, < 1.5.10
MEDIUM
6.1
CVE-2026-35539
Roundcube Webmail: Insufficient HTML attachment sanitization in preview mode
>= 1.7-beta, < 1.7-rc5
MEDIUM
5.4
CVE-2026-35540
Roundcube Webmail: Insufficient CSS sanitization in HTML e-mail messages
>= 1.7-beta, < 1.7-rc5
MEDIUM
5.3
Roundcube: Bypass of remote image blocking via crafted BODY background attribute
>= 1.7-beta, < 1.7-rc5
MEDIUM
5.3
Roundcube Webmail: Bypass of remote image blocking via SVG content (with animate attributes) in an e-mail message
>= 1.7-beta, < 1.7-rc5
MEDIUM
5.3
Roundcube Webmail: Remote image blocking feature can be bypassed via SVG content in an e-mail message
>= 1.7-beta, < 1.7-rc5
MEDIUM
5.3
Roundcube Webmail: Insufficient CSS sanitization in HTML e-mail messages
>= 1.7-beta, < 1.7-rc5
MEDIUM
4.2
Roundcube Webmail: Incorrect password comparison in the password plugin
>= 1.7-beta, < 1.7-rc5
LOW
3.7
Roundcube Webmail: Unsafe deserialization in the redis/memcache session handler
>= 1.7-beta, < 1.7-rc5
LOW
3.1
Roundcube Webmail: Unsanitized IMAP SEARCH command arguments
>= 1.7-beta, < 1.7-rc5
CVE-2026-35542
CVE-2026-35543
CVE-2026-35545
CVE-2026-35544
CVE-2026-35541
CVE-2026-35537
CVE-2026-35538