Known vulnerabilities in roundcube (Debian package)

Vendor: Debian
Software CPE: cpe:2.3:o:debian:roundcube_debian_package:*:*:*:*:*:debian_linux:*:*
Total vulnerabilities: 30
Public exploits: 7
Known exploited (KEV): 8
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting roundcube (Debian package) roundcube (Debian package) is affected by 30 known vulnerabilities: 1 critical, 5 high, 15 medium, 9 low Critical High Medium Low

Vulnerabilities (30)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU132212 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2026-48849
CWE-79 Low
No
No
1.6.5+dfsg-1+deb12u9, 1.6.16+dfsg-0+deb13u1 25.05.2026 SB2026052501
SB20260925257
#VU132213 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2026-48848
CWE-79 Medium
No
No
1.6.5+dfsg-1+deb12u9, 1.6.16+dfsg-0+deb13u1 25.05.2026 SB2026052501
SB20260925257
#VU132214 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2026-48842
CWE-89 Critical
No
No
1.6.5+dfsg-1+deb12u9, 1.6.16+dfsg-0+deb13u1 25.05.2026 SB2026052501
SB20260925257
#VU132215 - Server-Side Request Forgery (SSRF)
CVE-2026-48843
CWE-918 Medium
No
No
1.6.5+dfsg-1+deb12u9, 1.6.16+dfsg-0+deb13u1 25.05.2026 SB2026052501
SB20260925257
#VU132216 - Server-Side Request Forgery (SSRF)
CVE-2026-48845
CWE-918 Medium
No
No
1.6.5+dfsg-1+deb12u9, 1.6.16+dfsg-0+deb13u1 25.05.2026 SB2026052501
SB20260925257
#VU132217 - Improper input validation
CVE-2026-48846
CWE-20 Low
No
No
1.6.5+dfsg-1+deb12u9, 1.6.16+dfsg-0+deb13u1 25.05.2026 SB2026052501
SB20260925257
#VU132218 - External Control of File Name or Path
CVE-2026-48847
CWE-73 Medium
No
No
1.6.5+dfsg-1+deb12u9, 1.6.16+dfsg-0+deb13u1 25.05.2026 SB2026052501
SB20260925257
#VU132219 - Improper Control of Generation of Code ('Code Injection')
CVE-2026-48844
CWE-94 Medium
No
No
1.6.5+dfsg-1+deb12u9, 1.6.16+dfsg-0+deb13u1 25.05.2026 SB2026052501
SB20260925257
#VU122451 - Protection Mechanism Failure
CVE-2026-25916
CWE-693 Medium
Available
No
1.6.5+dfsg-1+deb12u7, 1.6.13+dfsg-0+deb13u1 08.02.2026 SB2026020801
SB2026021283
SB2026021284
and 5 more
#VU122450 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2026-26079
CWE-79 Medium
No
No
1.6.5+dfsg-1+deb12u7, 1.6.13+dfsg-0+deb13u1 08.02.2026 SB2026020801
SB2026021283
SB2026021284
and 5 more
#VU119953 - Exposure of sensitive information to an unauthorized actor
CVE-2025-68460
CWE-200 Low
No
No
1.6.5+dfsg-1+deb12u6, 1.6.12+dfsg-0+deb13u1 15.12.2025 SB2025121506
SB2025122339
#VU119952 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2025-68461
CWE-79 High
No
Exploited
1.6.5+dfsg-1+deb12u6, 1.6.12+dfsg-0+deb13u1 15.12.2025 SB2025121506
SB2025122339
SB2026033109
and 1 more
#VU110003 - Deserialization of Untrusted Data
CVE-2025-49113
CWE-502 High
Available
Exploited
1.6.5+dfsg-1+deb12u5 01.06.2025 SB2025060101
SB2025060331
SB2025060332
and 4 more
#VU95308 - Exposure of sensitive information to an unauthorized actor
CVE-2024-42010
CWE-200 Medium
Available
No
1.4.15+dfsg.1-1+deb11u4, 1.6.5+dfsg-1+deb12u3 05.08.2024 SB2024080505
SB2024080584
SB2024080585
and 4 more
#VU95299 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-42008
CWE-79 Low
Available
No
1.4.15+dfsg.1-1+deb11u4, 1.6.5+dfsg-1+deb12u3 05.08.2024 SB2024080505
SB2024080584
SB2024080585
and 4 more
#VU95292 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-42009
CWE-79 Low
Available
Exploited
1.4.15+dfsg.1-1+deb11u4, 1.6.5+dfsg-1+deb12u3 05.08.2024 SB2024080505
SB2024080584
SB2024080585
and 4 more
#VU89682 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-37384
CWE-79 Low
No
No
1.4.15+dfsg.1-1+deb11u3, 1.6.5+dfsg-1+deb12u2 21.05.2024 SB2024052107
SB2024052237
SB2024052238
and 3 more
#VU89681 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-37383
CWE-79 Medium
Available
Exploited
1.4.15+dfsg.1-1+deb11u3, 1.6.5+dfsg-1+deb12u2 21.05.2024 SB2024052107
SB2024052237
SB2024052238
and 3 more
#VU82893 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2023-47272
CWE-79 Medium
No
No
1.4.15+dfsg.1-1~deb11u2, 1.6.5+dfsg-1~deb12u1 07.11.2023 SB2023110748
SB2023110749
SB2023110750
and 4 more
#VU82083 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2023-5631
CWE-79 High
No
Exploited
1.4.15+dfsg.1-1~deb11u1, 1.6.4+dfsg-1~deb12u1 17.10.2023 SB2023101721
SB2023102405
SB2023102406
and 5 more


Showing elements 1 - 20 out of 30