Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1310 CNY

100%

webmail — Vulnerabilities & Security Advisories 27

All 27 CVE vulnerabilities found in webmail, with AI-generated Chinese analysis, references, and POCs.

This page serves as a centralized hub for the Webmail product, aggregating security vulnerability data related to common weakness classifications and associated tags within the email client domain. It compiles a comprehensive list of identified security flaws, including remote code execution, cross-site scripting, and authentication bypass issues, covering reports from the initial discovery phase through to the most recent patch deployments over the past five years. Readers can utilize this resource to track a vendor's advisories by monitoring the timeline of security updates and response times, gain a deeper understanding of a specific weakness class by analyzing frequency and severity trends across different releases, or look up a product's vulnerability history to assess the overall security posture and remediation effectiveness for web-based mail applications. The data is organized to facilitate quick reference for security analysts, developers, and IT administrators who need to evaluate risk exposure or verify the implementation of critical fixes. By presenting this information in a structured format, the page aims to support informed decision-making regarding patch management and system hardening strategies. All entries are sourced from official vendor announcements and verified security research databases, ensuring accuracy and reliability for professional use cases.

Vendor: Roundcube

CVE IDTitleCVSSSeverityPublished
CVE-2026-48849 Roundcube Webmail 跨站脚本漏洞 CWE-79 4.4 Medium2026-05-25
CVE-2026-48848 Roundcube Webmail 跨站脚本漏洞 CWE-79 7.2 High2026-05-25
CVE-2026-48847 Roundcube Webmail 安全漏洞 CWE-669 3.7 Low2026-05-25
CVE-2026-48846 Roundcube Webmail 安全漏洞 CWE-669 6.5 Medium2026-05-25
CVE-2026-48845 Roundcube Webmail 安全漏洞 CWE-669 6.5 Medium2026-05-25
CVE-2026-48844 Roundcube Webmail 安全漏洞 CWE-670 7.5 High2026-05-25
CVE-2026-48843 Roundcube Webmail 代码问题漏洞 CWE-918 7.2 High2026-05-25
CVE-2026-48842 Roundcube Webmail SQL注入漏洞 CWE-89 8.1 High2026-05-25
CVE-2026-35391 Bulwark Webmail getClientIP() trusted client-controlled X-Forwarded-For value, enabling rate limit bypass and audit log forgery CWE-348 9.1AICriticalAI2026-04-06
CVE-2026-35390 Content-Security-Policy was set to Report-Only mode, failing to block XSS attacks CWE-79 5.4AIMediumAI2026-04-06
CVE-2026-35389 Bulwark Webmail S/MIME signature verification accepted self-signed certificates CWE-295 5.3AIMediumAI2026-04-06
CVE-2026-35545 Roundcube Webmail 安全漏洞 CWE-669 5.3 Medium2026-04-03
CVE-2026-35544 Roundcube Webmail 安全漏洞 CWE-669 5.3 Medium2026-04-03
CVE-2026-35543 Roundcube Webmail 安全漏洞 CWE-669 5.3 Medium2026-04-03
CVE-2026-35542 Roundcube Webmail 安全漏洞 CWE-669 5.3 Medium2026-04-03
CVE-2026-35541 Roundcube Webmail 安全漏洞 CWE-843 4.2 Medium2026-04-03
CVE-2026-35540 Roundcube Webmail 安全漏洞 CWE-669 5.4 Medium2026-04-03
CVE-2026-35539 Roundcube Webmail 跨站脚本漏洞 CWE-79 6.1 Medium2026-04-03
CVE-2026-35538 Roundcube Webmail 参数注入漏洞 CWE-88 3.1 Low2026-04-03
CVE-2026-35537 Roundcube Webmail 代码问题漏洞 CWE-502 3.7 Low2026-04-03
CVE-2026-34834 Bulwark Webmail: Authentication Bypass in verifyIdentity() due to missing cookie validation CWE-287 8.2AIHighAI2026-04-02
CVE-2026-34833 Bulwark Webmail: Information Exposure: password returned in /api/auth/session CWE-312 7.5AIHighAI2026-04-02
CVE-2026-26079 Roundcube Webmail 安全漏洞 CWE-829 4.7 Medium2026-02-11
CVE-2026-25916 Roundcube Webmail 安全漏洞 CWE-420 4.3 Medium2026-02-09
CVE-2025-68461 Roundcube Webmail 跨站脚本漏洞 CWE-79 7.2 High2025-12-18
CVE-2025-68460 Roundcube Webmail 安全漏洞 CWE-116 7.2 High2025-12-18
CVE-2025-49113 Roundcube Webmail 安全漏洞 CWE-502 9.9 Critical2025-06-02

All 27 known CVE vulnerabilities affecting webmail with full Chinese analysis, references, and POCs where available.