Search CVE reports


Toggle filters

11 – 20 of 80 results


CVE-2024-38356

Medium priority
Needs evaluation

TinyMCE is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s content extraction code. When using the `noneditable_regexp` option, specially crafted HTML attributes containing...

2 affected packages

roundcube, tinymce

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
roundcube Needs evaluation Needs evaluation Needs evaluation Needs evaluation
tinymce Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2024-37385

Medium priority
Not affected

Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 on Windows allows command injection via im_convert_path and im_identify_path. NOTE: this issue exists because of an incomplete fix for CVE-2020-12641.

1 affected package

roundcube

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
roundcube Not affected Not affected Not affected Not affected
Show less packages

CVE-2024-37384

Medium priority
Fixed

Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via list columns from user preferences.

1 affected package

roundcube

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
roundcube Not affected Fixed Fixed Fixed
Show less packages

CVE-2024-37383

High priority
Fixed

Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.

1 affected package

roundcube

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
roundcube Not affected Fixed Fixed Fixed
Show less packages

CVE-2023-47272

Medium priority

Some fixes available 3 of 4

Roundcube 1.5.x before 1.5.6 and 1.6.x before 1.6.5 allows XSS via a Content-Type or Content-Disposition header (used for attachment preview or download).

1 affected package

roundcube

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
roundcube Not affected Fixed Fixed Not affected
Show less packages

CVE-2023-46267

Medium priority
Ignored

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-5631. Reason: This candidate is a duplicate of CVE-2023-5631. Notes: All CVE users should reference CVE-2023-5631 instead of this candidate. All references...

1 affected package

roundcube

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
roundcube Not affected Not affected Not affected
Show less packages

CVE-2023-5631

High priority

Some fixes available 4 of 5

Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a crafted SVG document because of program/lib/Roundcube/rcube_washtml.php behavior. This could allow a remote...

1 affected package

roundcube

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
roundcube Not affected Fixed Fixed Fixed
Show less packages

CVE-2023-43770

High priority

Some fixes available 5 of 6

Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of program/lib/Roundcube/rcube_string_replacer.php behavior.

1 affected package

roundcube

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
roundcube Not affected Fixed Fixed Fixed
Show less packages

CVE-2021-46144

Medium priority

Some fixes available 3 of 7

Roundcube before 1.4.13 and 1.5.x before 1.5.2 allows XSS via an HTML e-mail message with crafted Cascading Style Sheets (CSS) token sequences.

1 affected package

roundcube

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
roundcube Not affected Fixed Fixed Fixed
Show less packages

CVE-2021-44026

High priority

Some fixes available 3 of 5

Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.

1 affected package

roundcube

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
roundcube Not affected Not affected Fixed Fixed
Show less packages