← Vulnerability feed

Vulnerability record · CVE-2026-54433 · published 14 July 2026

CVE-2026-54433: Roundcube webmail cross-site scripting vulnerability

Roundcube · Webmail

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafted plain-text email message. The attacker-controlled JavaScript executes within the victim's authenticated session simply by opening or previewing the message (zero-click).

10.0 CVSS 3.1 Critical EPSS 0.31% · top 78.5% CWE-79 · Cross-site scripting
10.0CVSS 3.1 base score
0.31%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jul 2026Last modified by NVD

Description

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafted plain-text email message. The attacker-controlled JavaScript executes within the victim's authenticated session simply by opening or previewing the message (zero-click).

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-54433 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-44026Roundcube Webmail SQL injection via search parametersRoundcube Webmail before 1.3.17 and 1.4.x before 1.4.12 is prone to SQL injection through the search or search_params input. The flaw is remotely rea…KEVEPSS 70%analysed9.8CVE-2020-12641Roundcube Webmail OS command injection via image conversion path settingsRoundcube Webmail before 1.4.4 passes the im_convert_path and im_identify_path configuration settings to a shell without sanitization in rcube_image.…KEVEPSS 84%analysed9.3CVE-2024-42009Roundcube Webmail desanitization XSS in message_body()Roundcube Webmail through 1.5.7 and 1.6.x through 1.6.7 contains a cross-site scripting flaw caused by a desanitization issue in message_body() in pr…KEVEPSS 83%analysed8.8CVE-2025-49113Roundcube Webmail PHP Object Deserialization RCE via _from ParameterRoundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 fails to validate the _from parameter in program/actions/settings/upload.php, allowing PHP ob…KEVEPSS 99%analysed7.8CVE-2017-16651Roundcube Webmail file disclosure via attachment pluginRoundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows an authenticated user to read arbitrary files on the host filesyst…KEVEPSS 46%analysed6.1CVE-2025-68461Roundcube Webmail XSS via SVG animate tagRoundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is vulnerable to cross-site scripting through the animate tag in an SVG document. Because the f…KEVEPSS 27%analysed6.1CVE-2024-37383Roundcube Webmail XSS via SVG animate attributesRoundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 is vulnerable to cross-site scripting through SVG animate attributes. Because the flaw sits in …KEVEPSS 73%analysed6.1CVE-2023-43770Roundcube Webmail XSS via crafted links in plain-text emailsRoundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 is vulnerable to cross-site scripting because of how rcube_string_replacer.php ha…KEVEPSS 64%analysed

Source: NIST National Vulnerability Database (record CVE-2026-54433), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.