Roundcube
Browser-based IMAP webmail client with a desktop-like interface
After four years, Roundcube 1.7 lands — and the release stream is otherwise all CVEs
◆Recent moves
- 26d ago
Roundcube LTS patches attachment XSS, SSRF and a TNEF loop
The LTS half of a paired security release: stored XSS through an unescaped attachment MIME type, password-plugin flaws using a session-injected username, an SSRF bypass, and an infinite loop in the winmail.dat decoder. Standard for this line's cadence.
View source ↗ - 26d ago
Roundcube 1.7 gets the same attachment XSS and SSRF fixes
The stable-line twin of the 1.6.17 security release, shipped within a minute of it. The paired-release pattern is how Roundcube keeps LTS and stable users on the same security footing.
View source ↗ - 1mo ago
Roundcube LTS fixes a pre-auth SQL injection in virtuser_query
The most serious item in the window: a pre-authentication SQL injection in the virtuser_query plugin via a preg_replace escape bypass, alongside a CSS injection bypass through SVG animate and further SSRF fixes. Pre-auth reachability makes this one urgent for anyone running the plugin.
View source ↗ - 1mo ago
Roundcube 1.7.1 carries the pre-auth SQL injection fixes
The stable-line counterpart to 1.6.16, covering the same virtuser_query injection, sanitizer bypass and draft-restore XSS. Both lines patched the same afternoon.
View source ↗ - 2mo ago
Roundcube Webmail 1.7.0
⚡ SPARKThe only feature release in the window and the reference point for everything after it: four years of work landing breaking changes, a mandatory public_html/ entry point and modern OIDC support. The security releases that follow are hardening on top of this footing.
View source ↗ - 4mo ago
Roundcube 1.6.15 fixes an SVG animate bypass and search regressions
Patches remote image loading via SVG animate FUNCIRI attributes plus regressions from the prior release, including non-ASCII mail search failures. Regression repair alongside the vulnerability fix.
View source ↗