Known vulnerabilities in roundcube (Debian package)

Vendor: Debian
Software CPE: cpe:2.3:o:debian:roundcube_debian_package:*:*:*:*:*:debian_linux:*:*
Total vulnerabilities: 22
Public exploits: 7
Known exploited (KEV): 8
Highest CVSSv4 Score: 8.8

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting roundcube (Debian package) roundcube (Debian package) is affected by 22 known vulnerabilities: 5 high, 10 medium, 7 low Critical High Medium Low

Vulnerabilities (22)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU122451 - Protection Mechanism Failure
CVE-2026-25916
CWE-693 Medium
Available
No
1.6.5+dfsg-1+deb12u7, 1.6.13+dfsg-0+deb13u1 08.02.2026 SB2026020801
SB2026021283
SB2026021284
and 5 more
#VU122450 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2026-26079
CWE-79 Medium
No
No
1.6.5+dfsg-1+deb12u7, 1.6.13+dfsg-0+deb13u1 08.02.2026 SB2026020801
SB2026021283
SB2026021284
and 5 more
#VU119953 - Exposure of sensitive information to an unauthorized actor
CVE-2025-68460
CWE-200 Low
No
No
1.6.5+dfsg-1+deb12u6, 1.6.12+dfsg-0+deb13u1 15.12.2025 SB2025121506
SB2025122339
#VU119952 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2025-68461
CWE-79 High
No
Exploited
1.6.5+dfsg-1+deb12u6, 1.6.12+dfsg-0+deb13u1 15.12.2025 SB2025121506
SB2025122339
SB2026033109
and 1 more
#VU110003 - Deserialization of Untrusted Data
CVE-2025-49113
CWE-502 High
Available
Exploited
1.6.5+dfsg-1+deb12u5 01.06.2025 SB2025060101
SB2025060331
SB2025060332
and 4 more
#VU95308 - Exposure of sensitive information to an unauthorized actor
CVE-2024-42010
CWE-200 Medium
Available
No
1.4.15+dfsg.1-1+deb11u4, 1.6.5+dfsg-1+deb12u3 05.08.2024 SB2024080505
SB2024080584
SB2024080585
and 4 more
#VU95299 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-42008
CWE-79 Low
Available
No
1.4.15+dfsg.1-1+deb11u4, 1.6.5+dfsg-1+deb12u3 05.08.2024 SB2024080505
SB2024080584
SB2024080585
and 4 more
#VU95292 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-42009
CWE-79 Low
Available
Exploited
1.4.15+dfsg.1-1+deb11u4, 1.6.5+dfsg-1+deb12u3 05.08.2024 SB2024080505
SB2024080584
SB2024080585
and 4 more
#VU89682 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-37384
CWE-79 Low
No
No
1.4.15+dfsg.1-1+deb11u3, 1.6.5+dfsg-1+deb12u2 21.05.2024 SB2024052107
SB2024052237
SB2024052238
and 3 more
#VU89681 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-37383
CWE-79 Medium
Available
Exploited
1.4.15+dfsg.1-1+deb11u3, 1.6.5+dfsg-1+deb12u2 21.05.2024 SB2024052107
SB2024052237
SB2024052238
and 3 more
#VU82893 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2023-47272
CWE-79 Medium
No
No
1.4.15+dfsg.1-1~deb11u2, 1.6.5+dfsg-1~deb12u1 07.11.2023 SB2023110748
SB2023110749
SB2023110750
and 4 more
#VU82083 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2023-5631
CWE-79 High
No
Exploited
1.4.15+dfsg.1-1~deb11u1, 1.6.4+dfsg-1~deb12u1 17.10.2023 SB2023101721
SB2023102405
SB2023102406
and 5 more
#VU59318 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-46144
CWE-79 Medium
No
No
1.3.17+dfsg.1-1~deb10u2, 1.4.13+dfsg.1-1~deb11u1 09.01.2022 SB2022010901
SB2022010902
#VU58394 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2021-44026
CWE-89 High
Available
Exploited
1.3.17+dfsg.1-1~deb10u1, 1.4.12+dfsg.1-1~deb11u1 27.11.2021 SB2021112701
SB2021112702
SB2021111516
and 2 more
#VU58393 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-44025
CWE-79 Medium
No
No
1.3.17+dfsg.1-1~deb10u1, 1.4.12+dfsg.1-1~deb11u1 27.11.2021 SB2021112701
SB2021112702
SB2021111516
and 2 more
#VU49153 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-35730
CWE-79 High
No
Exploited
1.3.16+dfsg.1-1~deb10u1 28.12.2020 SB2020122805
SB2020122812
SB2021010410
and 2 more
#VU45648 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-16145
CWE-79 Low
No
No
1.3.15+dfsg.1-1~deb10u1 12.08.2020 SB2020081262
SB2020081270
SB2020092414
and 2 more
#VU29609 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-15562
CWE-79 Medium
No
No
1.3.14+dfsg.1-1~deb10u1 09.07.2020 SB2020070909
SB2020070910
SB2020092414
#VU28979 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-13965
CWE-79 Medium
No
Exploited
1.2.3+dfsg.1-4+deb9u5, 1.3.13+dfsg.1-1~deb10u1 11.06.2020 SB2020061115
SB2020061116
SB2020060828
and 1 more
#VU28978 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-13964
CWE-79 Medium
No
No
1.2.3+dfsg.1-4+deb9u5, 1.3.13+dfsg.1-1~deb10u1 11.06.2020 SB2020061115
SB2020061116
SB2020060828
and 1 more


Showing elements 1 - 20 out of 22