Product of Roundcube

Webmail

As of , 7 Roundcube Webmail vulnerabilities are on CISA's list of exploited vulnerabilities; 2 were added in 2026. Patch first: CVE-2025-49113.

Patch first

Patch first
#VulnerabilityProductOur groupListedDeadlineEPSS
1CVE-2025-49113Deserialization of Untrusted DataRoundcube WebmailPatch this weekMetasploit module; EPSS 0.990.99
2CVE-2024-42009Cross-Site ScriptingRoundcube WebmailPatch this weekEPSS 0.830.83
3CVE-2024-37383Cross-Site Scripting (XSS)Roundcube WebmailPatch this weekEPSS 0.730.73
4CVE-2020-13965Cross-Site Scripting (XSS)Roundcube WebmailPatch this weekEPSS 0.770.77
5CVE-2023-43770Persistent Cross-Site Scripting (XSS)Roundcube WebmailPatch this weekEPSS 0.640.64
6CVE-2023-5631Persistent Cross-Site Scripting (XSS)Roundcube WebmailPatch this weekEPSS 0.760.76
7CVE-2025-68461Cross-site ScriptingRoundcube WebmailPatch soon0.27

Added each year

1232023: 1120232024: 3320242025: 1120252026: 222026
Entries CISA added each year, removed ones included. Source: CISA KEV.
Show the numbers
Periodentries added
20231
20243
20251
20262

Used in ransomware