FLAT-P06A4Â (CVE-2026-75010)
Business information leak In roundcube
0.6
Low
Ecosystem: Debian
Component: roundcube
FLAT-0CLOPÂ (CVE-2026-75004)
Security controls bypass or absence In roundcube
1.7
Low
Ecosystem: Debian
Component: roundcube
FLAT-CPOIUÂ (CVE-2026-75007)
OS Command Injection In roundcube
5.9
Medium
Ecosystem: Debian
Component: roundcube
FLAT-RH8GBÂ (CVE-2026-75006)
Reflected cross-site scripting (XSS) In roundcube
0.6
Low
Ecosystem: Debian
Component: roundcube
FLAT-KXM6HÂ (CVE-2026-75003)
Sensitive information sent insecurely In roundcube
2.7
Low
Ecosystem: Debian
Component: roundcube
FLAT-98BN8Â (CVE-2026-74999)
Server side cross-site scripting In roundcube
2.3
Low
Ecosystem: Debian
Component: roundcube
FLAT-28F8LÂ (CVE-2026-75000)
Reflected cross-site scripting (XSS) In roundcube
1.2
Low
Ecosystem: Debian
Component: roundcube
FLAT-TAIIIÂ (CVE-2026-75002)
Lack of data validation In roundcube
6.2
Medium
Ecosystem: Debian
Component: roundcube
FLAT-22DN7Â (CVE-2026-74998)
Reflected cross-site scripting (XSS) In roundcube
0.5
Low
Ecosystem: Debian
Component: roundcube
FLAT-FYJ7UÂ (CVE-2026-74997)
Lack of data validation In roundcube
5.2
Medium
Ecosystem: Debian
Component: roundcube
FLAT-UONFJÂ (CVE-2026-54432)
Server side cross-site scripting In roundcube
2.4
Low
Ecosystem: Debian
Component: roundcube
FLAT-8EAZIÂ (CVE-2026-54433)
Server side cross-site scripting In roundcube
7.4
High
Ecosystem: Debian
Component: roundcube
FLAT-LE8DIÂ (CVE-2026-62642)
Improper resource allocation In roundcube
4.3
Medium
Ecosystem: Debian
Component: roundcube
FLAT-W79GDÂ (CVE-2026-62643)
Reflected cross-site scripting (XSS) In roundcube
0.5
Low
Ecosystem: Debian
Component: roundcube
FLAT-CYMYMÂ (CVE-2026-62641)
Asymmetric denial of service - ReDoS In roundcube
6.6
Medium
Ecosystem: Debian
Component: roundcube
FLAT-ADJ1DÂ (CVE-2026-62644)
Session Fixation In roundcube
6.9
Medium
Ecosystem: Debian
Component: roundcube
FLAT-ST3WZÂ (CVE-2026-48849)
Server side cross-site scripting In roundcube
0.5
Low
Ecosystem: Debian
Component: roundcube
FLAT-HEU72Â (CVE-2026-48847)
Anonymous connection In roundcube
4.8
Medium
Ecosystem: Debian
Component: roundcube
FLAT-4HJGHÂ (CVE-2026-48848)
OS Command Injection In roundcube
2.7
Low
Ecosystem: Debian
Component: roundcube
FLAT-DQ7XVÂ (CVE-2026-48846)
Cross-site request forgery In roundcube
1.3
Low
Ecosystem: Debian
Component: roundcube
FLAT-K8N0RÂ (CVE-2026-48845)
Improper authorization control for web services In roundcube
2.7
Low
Ecosystem: Debian
Component: roundcube
FLAT-2ZAPHÂ (CVE-2026-48843)
Reflected cross-site scripting (XSS) In roundcube
1.7
Low
Ecosystem: Debian
Component: roundcube
FLAT-HDKOKÂ (CVE-2026-48844)
Lack of data validation In roundcube
5.2
Medium
Ecosystem: Debian
Component: roundcube
FLAT-YBTT7Â (CVE-2026-48842)
SQL injection In roundcube
7.2
High
Ecosystem: Debian
Component: roundcube
FLAT-ELF7QÂ (DLA-4517-1)
Use of software with malware In roundcube
6.0
Medium
Ecosystem: Debian
Component: roundcube
FLAT-LTM37Â (DSA-6137-1)
Use of software with malware In roundcube
6.1
Medium
Ecosystem: Debian
Component: roundcube
FLAT-T2CBIÂ (DLA-4480-1)
Use of software with malware In roundcube
6.1
Medium
Ecosystem: Debian
Component: roundcube
FLAT-0VYY2Â (CVE-2026-26079)
Server side template injection In roundcube
1.3
Low
Ecosystem: Debian
Component: roundcube
FLAT-XQY7SÂ (CVE-2026-25916)
Clickjacking In roundcube
0.6
Low
Ecosystem: Debian
Component: roundcube
FLAT-MMS8ZÂ (DSA-6087-1)
Use of software with malware In roundcube
6.1
Medium
Ecosystem: Debian
Component: roundcube
FLAT-F7PB9Â (CVE-2025-68461)
Reflected cross-site scripting (XSS) In roundcube
2.3
Low
Ecosystem: Debian
Component: roundcube
FLAT-ELAB0Â (CVE-2025-68460)
Reflected cross-site scripting (XSS) In roundcube
1.3
Low
Ecosystem: Debian
Component: roundcube
FLAT-351Z3Â (DLA-4415-1)
Use of software with malware In roundcube
6.1
Medium
Ecosystem: Debian
Component: roundcube
FLAT-B3G7QÂ (DLA-4211-1)
Use of software with malware In roundcube
5.2
Medium
Ecosystem: Debian
Component: roundcube
FLAT-K350TÂ (DSA-5934-1)
Use of software with malware In roundcube
5.2
Medium
Ecosystem: Debian
Component: roundcube
FLAT-IP7ROÂ (CVE-2024-57004)
Server side cross-site scripting In roundcube
1.3
Low
Ecosystem: Debian
Component: roundcube
FLAT-GAR0PÂ (DSA-5743-2)
Server side cross-site scripting In roundcube
1.3
Low
Ecosystem: Debian
Component: roundcube
FLAT-RIP3LÂ (DSA-5743-1)
Server side cross-site scripting In roundcube
1.3
Low
Ecosystem: Debian
Component: roundcube
FLAT-PPH2VÂ (CVE-2024-42008)
Server side cross-site scripting In roundcube
7.3
High
Ecosystem: Debian
Component: roundcube
FLAT-R7SVGÂ (CVE-2024-42009)
Server side cross-site scripting In roundcube
7.5
High
Ecosystem: Debian
Component: roundcube
FLAT-DM1ALÂ (CVE-2024-42010)
Server side cross-site scripting In roundcube
1.3
Low
Ecosystem: Debian
Component: roundcube
FLAT-FS8GBÂ (DSA-5714-1)
Server side cross-site scripting In roundcube
1.3
Low
Ecosystem: Debian
Component: roundcube
FLAT-VCFP3Â (DLA-3835-1)
Server side cross-site scripting In roundcube
1.3
Low
Ecosystem: Debian
Component: roundcube
FLAT-QMCUNÂ (CVE-2024-37383)
Server side cross-site scripting In roundcube
1.3
Low
Ecosystem: Debian
Component: roundcube
FLAT-KVXSPÂ (CVE-2024-37384)
Server side cross-site scripting In roundcube
1.3
Low
Ecosystem: Debian
Component: roundcube
FLAT-ASCB5Â (DLA-3683-1)
Server side cross-site scripting In roundcube
1.3
Low
Ecosystem: Debian
Component: roundcube
FLAT-JLUQZÂ (DSA-5572-1)
Server side cross-site scripting In roundcube
1.3
Low
Ecosystem: Debian
Component: roundcube
FLAT-PAREQÂ (CVE-2023-47272)
Server side cross-site scripting In roundcube
1.3
Low
Ecosystem: Debian
Component: roundcube
FLAT-22M8KÂ (DLA-3630-1)
Server side cross-site scripting In roundcube
1.3
Low
Ecosystem: Debian
Component: roundcube
FLAT-RSCGIÂ (DSA-5531-1)
Server side cross-site scripting In roundcube
1.3
Low
Ecosystem: Debian
Component: roundcube
FLAT-11IN4Â (CVE-2023-5631)
Server side cross-site scripting In roundcube
1.2
Low
Ecosystem: Debian
Component: roundcube
FLAT-7LGSLÂ (CVE-2023-43770)
Server side cross-site scripting In roundcube
1.3
Low
Ecosystem: Debian
Component: roundcube
FLAT-F318EÂ (DLA-3577-1)
Server side cross-site scripting In roundcube
1.3
Low
Ecosystem: Debian
Component: roundcube
FLAT-5W2G4Â (DLA-2878-1)
Server side cross-site scripting In roundcube
1.3
Low
Ecosystem: Debian
Component: roundcube
FLAT-54QDBÂ (DSA-5037-1)
Server side cross-site scripting In roundcube
1.3
Low
Ecosystem: Debian
Component: roundcube
FLAT-IXUWLÂ (CVE-2021-46144)
Server side cross-site scripting In roundcube
1.3
Low
Ecosystem: Debian
Component: roundcube
FLAT-L648HÂ (DLA-2840-1)
Server side cross-site scripting In roundcube
1.3
Low
Ecosystem: Debian
Component: roundcube
FLAT-UIDJNÂ (DSA-5013-1)
Server side cross-site scripting In roundcube
1.3
Low
Ecosystem: Debian
Component: roundcube
FLAT-FW0VQÂ (CVE-2021-44026)
SQL injection In roundcube
6.3
Medium
Ecosystem: Debian
Component: roundcube
FLAT-38SLAÂ (CVE-2021-44025)
Server side cross-site scripting In roundcube
1.3
Low
Ecosystem: Debian
Component: roundcube
FLAT-BT2S3Â (CVE-2020-18670)
Server side cross-site scripting In roundcube
1.2
Low
Ecosystem: Debian
Component: roundcube
FLAT-4I6YEÂ (CVE-2020-18671)
Server side cross-site scripting In roundcube
1.2
Low
Ecosystem: Debian
Component: roundcube
FLAT-4TPOSÂ (DSA-4821-1)
Server side cross-site scripting In roundcube
1.3
Low
Ecosystem: Debian
Component: roundcube
FLAT-T0V15Â (DLA-2508-1)
Server side cross-site scripting In roundcube
1.3
Low
Ecosystem: Debian
Component: roundcube
FLAT-54EQAÂ (CVE-2020-16145)
Server side cross-site scripting In roundcube
1.3
Low
Ecosystem: Debian
Component: roundcube
FLAT-XX6VBÂ (DSA-4744-1)
Server side cross-site scripting In roundcube
1.3
Low
Ecosystem: Debian
Component: roundcube
FLAT-9MY03Â (DLA-2322-1)
Server side cross-site scripting In roundcube
1.3
Low
Ecosystem: Debian
Component: roundcube
FLAT-TRKJRÂ (DSA-4720-1)
Server side cross-site scripting In roundcube
1.3
Low
Ecosystem: Debian
Component: roundcube
FLAT-IK21RÂ (CVE-2020-15562)
Server side cross-site scripting In roundcube
1.3
Low
Ecosystem: Debian
Component: roundcube
FLAT-IJQRDÂ (DSA-4700-1)
Server side cross-site scripting In roundcube
1.3
Low
Ecosystem: Debian
Component: roundcube
FLAT-663RAÂ (CVE-2020-13965)
Server side cross-site scripting In roundcube
1.3
Low
Ecosystem: Debian
Component: roundcube
FLAT-HB953Â (CVE-2020-13964)
Server side cross-site scripting In roundcube
1.3
Low
Ecosystem: Debian
Component: roundcube
FLAT-CMLIIÂ (DSA-4674-1)
Server side cross-site scripting In roundcube
1.3
Low
Ecosystem: Debian
Component: roundcube
FLAT-DXQOLÂ (CVE-2020-12641)
OS Command Injection In roundcube
6.3
Medium
Ecosystem: Debian
Component: roundcube
FLAT-ZI10QÂ (CVE-2020-12640)
Local file inclusion In roundcube
8.1
High
Ecosystem: Debian
Component: roundcube
FLAT-EBWTIÂ (CVE-2020-12626)
Insecure service configuration In roundcube
5.1
Medium
Ecosystem: Debian
Component: roundcube
FLAT-OAPINÂ (CVE-2020-12625)
Server side cross-site scripting In roundcube
1.3
Low
Ecosystem: Debian
Component: roundcube
FLAT-YV28QÂ (CVE-2019-15237)
Weak credential policy In roundcube
4.6
Medium
Ecosystem: Debian
Component: roundcube
FLAT-0Z7KUÂ (CVE-2019-10740)
Sensitive information sent insecurely In roundcube
2.3
Low
Ecosystem: Debian
Component: roundcube
FLAT-7247HÂ (DSA-4344-1)
Server side cross-site scripting In roundcube
1.3
Low
Ecosystem: Debian
Component: roundcube
FLAT-AI6M0Â (CVE-2018-19205)
Unauthorized access to screen In roundcube
6.6
Medium
Ecosystem: Debian
Component: roundcube
FLAT-CJ3KQÂ (CVE-2018-19206)
Server side cross-site scripting In roundcube
1.3
Low
Ecosystem: Debian
Component: roundcube
FLAT-IG9BCÂ (DSA-4181-1)
Server side cross-site scripting In roundcube
1.3
Low
Ecosystem: Debian
Component: roundcube
FLAT-VAX3DÂ (CVE-2018-1000071)
Unauthorized access to screen In roundcube
6.6
Medium
Ecosystem: Debian
Component: roundcube
FLAT-Z1OEVÂ (DLA-1193-1)
Server side cross-site scripting In roundcube
1.3
Low
Ecosystem: Debian
Component: roundcube
FLAT-B2SPHÂ (DSA-4030-1)
Server side cross-site scripting In roundcube
1.3
Low
Ecosystem: Debian
Component: roundcube
FLAT-U6DZQÂ (DLA-613-2)
Lack of data validation In roundcube
1.3
Low
Ecosystem: Debian
Component: roundcube
FLAT-A6SOUÂ (CVE-2015-5381)
Server side cross-site scripting In roundcube
1.3
Low
Ecosystem: Debian
Component: roundcube
FLAT-1388MÂ (CVE-2015-5382)
Lack of data validation - Path Traversal In roundcube
4.9
Medium
Ecosystem: Debian
Component: roundcube
FLAT-GR3XTÂ (DLA-933-1)
Server side cross-site scripting In roundcube
1.3
Low
Ecosystem: Debian
Component: roundcube
FLAT-9WW14Â (CVE-2016-4068)
Server side cross-site scripting In roundcube
1.3
Low
Ecosystem: Debian
Component: roundcube
FLAT-2KFSAÂ (CVE-2015-8864)
Server side cross-site scripting In roundcube
1.3
Low
Ecosystem: Debian
Component: roundcube
FLAT-NW0QZÂ (DLA-855-1)
Server side cross-site scripting In roundcube
1.3
Low
Ecosystem: Debian
Component: roundcube
FLAT-A8AW8Â (CVE-2015-2180)
OS Command Injection In roundcube
6.3
Medium
Ecosystem: Debian
Component: roundcube
FLAT-Q9NMZÂ (CVE-2015-2181)
Improper resource allocation - Buffer overflow In roundcube
6.3
Medium
Ecosystem: Debian
Component: roundcube
FLAT-1R9Z0Â (CVE-2016-4552)
Server side cross-site scripting In roundcube
1.3
Low
Ecosystem: Debian
Component: roundcube
FLAT-DAFSNÂ (CVE-2016-9920)
Lack of data validation In roundcube
5.2
Medium
Ecosystem: Debian
Component: roundcube
FLAT-OVNICÂ (DLA-737-1)
Server side cross-site scripting In roundcube
1.3
Low
Ecosystem: Debian
Component: roundcube
FLAT-6HASYÂ (DLA-613-1)
Server side cross-site scripting In roundcube
1.3
Low
Ecosystem: Debian
Component: roundcube
FLAT-2LTSEÂ (CVE-2016-4069)
Cross-site request forgery In roundcube
5.2
Medium
Ecosystem: Debian
Component: roundcube