Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the cmd_learn driver of the markasjunk plugin is subject to remote code execution via… (CVE-2026-74997)CVE-2026-74997
0

Roundcube Webmail versions before 1.6.18 and 1.7.x before 1.7.3 are vulnerable to remote code execution via the cmd_learn driver of the markasjunk plugin. This vulnerability arises from crafted placeholder replacement values and affects only instances using this specific plugin driver. The vulnerability has a high severity with a CVSS score of 8.8.

Join the discussion
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper rule name quoting could lead to managesieve_disabled_actions setting bypass via… (CVE-2026-75004)CVE-2026-75004
0

Roundcube Webmail versions before 1.6.18 and 1.7.x before 1.7.3 contain a vulnerability in the managesieve plugin where improper quoting of rule names can allow bypassing the managesieve_disabled_actions setting via a crafted Sieve script rule name. This vulnerability has a moderate severity score and does not affect confidentiality or availability but impacts integrity. No official patch or remediation details are provided in the available data.

Join the discussion
CVE-2026-75000: CWE-669 Incorrect Resource Transfer Between Spheres in Roundcube WebmailCVE-2026-75000
0

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper HTML/CSS sanitization of the SVG animate "by" attribute may lead to remote image blocking bypass, which in turn may lead to information disclosure or privilege escalation.

Join the discussion
CVE-2026-75002: CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection') in Roundcube WebmailCVE-2026-75002
0

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, mail search and LITERAL+ byte-count desynchronization could lead to information disclosure or privilege escalation via IMAP command injection.

Join the discussion
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the "Add to address book" action was subject to stored XSS. (CVE-2026-74999)CVE-2026-74999
0

Roundcube Webmail versions before 1.6.18 and 1.7.x before 1.7.3 contain a stored cross-site scripting (XSS) vulnerability in the "Add to address book" feature. This vulnerability allows an attacker with limited privileges and user interaction to inject malicious scripts that can affect confidentiality and integrity but does not impact availability. The issue is identified as CVE-2026-74999 with a CVSS score of 5.4 (medium severity).

Join the discussion
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the modoboa driver of the password plugin could leak a Modoboa API authentication token… (CVE-2026-75010)CVE-2026-75010
0

A vulnerability in Roundcube Webmail versions before 1.6.18 and 1.7.x before 1.7.3 allows the modoboa driver of the password plugin to leak a Modoboa API authentication token. This leakage occurs via crafted session data and affects only Roundcube instances using the password plugin with the modoboa driver. The vulnerability has a CVSS score of 6.4, indicating a medium severity.

Join the discussion
CVE-2026-75007: CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection') in Roundcube WebmailCVE-2026-75007
0

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the LDAP search filter was subject to injection via unescaped %u/%fu/%d substitution, which may lead to information disclosure or privilege escalation.

Join the discussion
CVE-2026-75003: CWE-669 Incorrect Resource Transfer Between Spheres in Roundcube WebmailCVE-2026-75003
0

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed url() in a FuncIRI attribute of an SVG image could evade the remote image blocking, which may lead to information disclosure or privilege escalation.

Join the discussion
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead… (CVE-2026-75006)CVE-2026-75006
0

Roundcube Webmail versions before 1.6.18 and 1.7.x before 1.7.3 have insufficient sanitization of Cascading Style Sheets (CSS) in HTML email messages. This vulnerability may allow Server-Side Request Forgery (SSRF) or information disclosure if stylesheet links point to local network hosts. The issue stems from incomplete fixes of previous related vulnerabilities.

Join the discussion
CVE-2026-74998: CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') in Roundcube WebmailCVE-2026-74998
0

CVE-2026-74998 is a high-severity cross-site scripting (XSS) vulnerability in Roundcube Webmail. It affects versions before 1.6.18 and 1.7.x before 1.7.3. The issue arises because responses from the CSS proxy were not properly validated, potentially allowing information disclosure or XSS attacks via MIME sniffing.

Join the discussion

Showing 1 to 10 of 10 results

Filters:Package: pkg:github/roundcube/roundcubemail
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses