Exposición de RoundCube

Webmail
116
score de exposición
1483
sitios usan
3
en explotación
1
críticos
Análisis Vexday

RoundCube apresenta uma taxa de exploração ativa expressivamente acima da média do catálogo CISA KEV, com 3 de suas 23 CVEs catalogadas confirmadas em uso por agentes maliciosos — proporção 29 vezes superior à média geral, o que indica histórico concreto de aproveitamento oportunista dessa superfície de ataque. O volume recente é igualmente preocupante: 17 vulnerabilidades surgiram nos últimos 90 dias, sugerindo aumento relevante na atenção de pesquisadores e atacantes à plataforma. A CVE mais crítica atualmente ativa, CVE-2025-49113, registra EPSS de 0,89, valor próximo ao teto da escala, sinalizando altíssima probabilidade de exploração iminente ou em curso. Equipes responsáveis por instâncias RoundCube devem tratar a aplicação de patches como prioridade imediata, com atenção especial às falhas classificadas sob CWE-669, padrão de fraqueza dominante no conjunto de vulnerabilidades desta tecnologia.

CVEs

29 resultados
CVE-2026-48843HIGHRoundcube Webmail 1.6.x between 1.6.14 and 1.6.16,and 1.7.x before 1.7.1 has Insufficient Cascading Style Sheets (CSS) sanitization in HTML EPSS 0.3%CVE-2026-62644MEDIUMIn Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing viaEPSS 0.3%CVE-2025-68460HIGHRoundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a information disclosure vulnerability in the HTML style sanitizer.EPSS 0.3%CVE-2026-62641MEDIUMIn Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the TNEF decoder was subject to denial of service via a crafted compressed-RTF siEPSS 0.3%CVE-2026-35539MEDIUMAn issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. XSS exists because of insufficient HTML attachment sanitization in prEPSS 0.3%CVE-2026-62643HIGHIn Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages maEPSS 0.2%CVE-2026-35541MEDIUMAn issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Incorrect password comparison in the password plugin could lead to tyEPSS 0.2%CVE-2026-48849MEDIUMIn Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, an unsanitized subject field in the draft restored value could lead to storEPSS 0.2%CVE-2026-54432MEDIUMRoundcube Webmail before 1.6.17 and 1.7.x before 1.7.2 allows Stored Cross-Site Scripting (XSS). The issue occurs because the attachment MIMEPSS 0.2%