Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5049 articles · 189092 vulns · 37/41 feeds (7d)
← Back to list
7.2
CVE-2026-54433PATCHED
roundcube · webmail

CVE-2026-54433: In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafted plai

Description

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafted plain-text email message. The attacker-controlled JavaScript executes within the victim's authenticated session simply by opening or previewing the message (zero-click).

Affected Products

VendorProductVersions
roundcubewebmail1.6.0, 1.7.0

References

  • https://roundcube.net/news/2026/07/05/security-updates-1.6.17-and-1.7.2

Related News (3 articles)

Tier C
VulDB29d ago
CVE-2026-54433 | Roundcube up to 1.6.16/1.7.1 Email Message cross site scripting
→ No new info (linked only)
Tier B
BSI Advisories37d ago
[NEU] [mittel] Roundcube: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
CERT-FR37d ago
Multiples vulnérabilités dans Roundcube (06 juillet 2026)
→ No new info (linked only)
CVSS 3.17.2 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
CISA KEV❌ No
Actively exploited❌ No
Patch available
1.6.171.7.2
CWECWE-79
PublishedJul 14, 2026
Last enriched29d agov2
Trending Score2
Source articles3
Independent3
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

MEDIUMCVE-2026-54432
CVE-2026-54432: Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2 allows Stored Cross-Site Scripting (XSS). The issue occurs becaus
Trending: 4
CRITICALCVE-2026-62644EXP
CVE-2026-62644: In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to u
Trending: 1
HIGHCVE-2026-62642EXP
CVE-2026-62642: In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, an infinite loop was discovered in the TNEF decoder, which ma
Trending: 1
HIGHCVE-2026-62641
CVE-2026-62641: In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the TNEF decoder was subject to denial of service via a craft
Trending: 1
HIGHCVE-2026-62643EXP
CVE-2026-62643: In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sheets (CSS) sanitization in HTM
Trending: 1

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 14, 2026
Discovered by ZDM
Jul 14, 2026
Updated: affectedVersions
Jul 14, 2026
Patch Available
Jul 15, 2026

Version History

v2
Last enriched 29d ago
v2Tier C29d ago

Updated affected versions to include 1.6.16 and 1.7.1, and clarified that no exploit is available.

affectedVersions
via VulDB
v129d ago

Initial creation