← Vulnerability feed

Vulnerability record · CVE-2024-42008 · published 5 August 2024

CVE-2024-42008: Roundcube webmail cross-site scripting vulnerability

Roundcube · Webmail

A Cross-Site Scripting vulnerability in rcmail_action_mail_get->run() in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a malicious e-mail attachment served with a dangerous Content-Type header.

9.3 CVSS 3.1 Critical EPSS 34% · top 1.6% CWE-79 · Cross-site scripting
9.3CVSS 3.1 base score
34%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
5References
17 Jun 2026Last modified by NVD

Description

A Cross-Site Scripting vulnerability in rcmail_action_mail_get->run() in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a malicious e-mail attachment served with a dangerous Content-Type header.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-42008 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-44026Roundcube Webmail SQL injection via search parametersRoundcube Webmail before 1.3.17 and 1.4.x before 1.4.12 is prone to SQL injection through the search or search_params input. The flaw is remotely rea…KEVEPSS 70%analysed9.8CVE-2020-12641Roundcube Webmail OS command injection via image conversion path settingsRoundcube Webmail before 1.4.4 passes the im_convert_path and im_identify_path configuration settings to a shell without sanitization in rcube_image.…KEVEPSS 84%analysed9.3CVE-2024-42009Roundcube Webmail desanitization XSS in message_body()Roundcube Webmail through 1.5.7 and 1.6.x through 1.6.7 contains a cross-site scripting flaw caused by a desanitization issue in message_body() in pr…KEVEPSS 83%analysed8.8CVE-2025-49113Roundcube Webmail PHP Object Deserialization RCE via _from ParameterRoundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 fails to validate the _from parameter in program/actions/settings/upload.php, allowing PHP ob…KEVEPSS 99%analysed7.8CVE-2017-16651Roundcube Webmail file disclosure via attachment pluginRoundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows an authenticated user to read arbitrary files on the host filesyst…KEVEPSS 46%analysed6.1CVE-2025-68461Roundcube Webmail XSS via SVG animate tagRoundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is vulnerable to cross-site scripting through the animate tag in an SVG document. Because the f…KEVEPSS 27%analysed6.1CVE-2024-37383Roundcube Webmail XSS via SVG animate attributesRoundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 is vulnerable to cross-site scripting through SVG animate attributes. Because the flaw sits in …KEVEPSS 73%analysed6.1CVE-2023-43770Roundcube Webmail XSS via crafted links in plain-text emailsRoundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 is vulnerable to cross-site scripting because of how rcube_string_replacer.php ha…KEVEPSS 64%analysed

Source: NIST National Vulnerability Database (record CVE-2024-42008), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.