Roundcube Webmail

Roundcube · current 1.7.3

Are you Roundcube? Claim this page

The current version of Roundcube Webmail is 1.7.3 (as of 09/08/2026). patchletter checks the official source daily and emails you new releases.

Actively exploited vulnerabilities

The US cybersecurity agency CISA lists these vulnerabilities in its catalog of Known Exploited Vulnerabilities. What CISA does not carry does not appear in this list — even where it is being exploited.

  • CVE-2021-44026Roundcube Webmail SQL Injection Vulnerability

    9.8 critical · over the network, without login · CISA deadline was 13 Jul 23

  • CVE-2020-12641Roundcube Webmail Remote Code Execution Vulnerability

    9.8 critical · over the network, without login · CISA deadline was 13 Jul 23

  • CVE-2024-42009RoundCube Webmail Cross-Site Scripting Vulnerability

    9.3 critical · over the network, without login, needs user action · CISA deadline was 30 Jun 25

  • CVE-2025-49113RoundCube Webmail Deserialization of Untrusted Data Vulnerability

    8.8 high · over the network, with a basic account · CISA deadline was 13 Mar

  • CVE-2017-16651Roundcube Webmail File Disclosure Vulnerability

    7.8 high · locally only, with a basic account · CISA deadline was 3 May 22

  • CVE-2023-43770Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability

    6.1 medium · over the network, without login, needs user action · CISA deadline was 4 Mar 24

  • CVE-2020-13965Roundcube Webmail Cross-Site Scripting (XSS) Vulnerability

    6.1 medium · over the network, without login, needs user action · CISA deadline was 17 Jul 24

  • CVE-2024-37383RoundCube Webmail Cross-Site Scripting (XSS) Vulnerability

    6.1 medium · over the network, without login, needs user action · CISA deadline was 14 Nov 24

  • CVE-2025-68461RoundCube Webmail Cross-site Scripting Vulnerability

    6.1 medium · over the network, without login, needs user action · CISA deadline was 13 Mar

  • CVE-2020-35730Roundcube Webmail Cross-Site Scripting (XSS) Vulnerability

    6.1 medium · over the network, without login, needs user action · CISA deadline was 13 Jul 23

  • CVE-2023-5631Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability

    5.4 medium · over the network, with a basic account, needs user action · CISA deadline was 16 Nov 23

Source: CISA KEV. The CVE is matched to the product automatically — when in doubt, the linked NVD entry applies.

BSI security advisories

Advisories the German BSI (CERT-Bund) published for this product. Whether your version is affected is stated in the advisory itself.

All BSI advisories →

Version history & changelog · as detected by patchletter

VersionChannelDateNotes
1.7.3STABLE09/08/2026Release notes →
1.7.2STABLE05/07/2026Release notes →
1.7.1STABLE24/05/2026Release notes →
1.7.0STABLE10/05/2026Release notes →
1.6.17STABLE05/07/2026Release notes →
1.6.16STABLE24/05/2026Release notes →
1.6.15STABLE29/03/2026Release notes →
1.6.14STABLE18/03/2026Release notes →
1.6.13STABLE08/02/2026Release notes →
1.6.12STABLE14/12/2025Release notes →
1.6.11STABLE01/06/2025Release notes →
1.6.10STABLE08/02/2025Release notes →
1.6.9STABLE01/09/2024Release notes →
1.6.8STABLE04/08/2024Release notes →
1.6.7STABLE19/05/2024Release notes →
1.6.6STABLE20/01/2024Release notes →
1.6.5STABLE05/11/2023Release notes →
1.6.4STABLE16/10/2023Release notes →
1.6.3STABLE15/09/2023Release notes →
1.6.2STABLE02/07/2023Release notes →
1.6.1STABLE23/01/2023Release notes →
1.6.0STABLE28/07/2022Release notes →
1.5.15STABLE29/03/2026Release notes →
1.5.14STABLE18/03/2026Release notes →
1.5.13STABLE08/02/2026Release notes →
1.5.12STABLE14/12/2025Release notes →
1.5.11STABLE15/06/2025Release notes →
1.5.10STABLE01/06/2025Release notes →
1.5.9STABLE01/09/2024Release notes →
1.5.8STABLE04/08/2024Release notes →
1.5.7STABLE19/05/2024Release notes →
1.5.6STABLE05/11/2023Release notes →
1.5.5STABLE16/10/2023Release notes →
1.5.4STABLE18/09/2023Release notes →
1.5.3STABLE26/06/2022Release notes →
1.5.2STABLE30/12/2021Release notes →
1.5.1STABLE28/11/2021Release notes →
1.5.0STABLE18/10/2021Release notes →
1.4.15STABLE16/10/2023Release notes →
1.4.14STABLE18/09/2023Release notes →
1.4.13STABLE30/12/2021Release notes →
1.4.12STABLE12/11/2021Release notes →
1.4.11STABLE08/02/2021Release notes →
1.4.10STABLE27/12/2020Release notes →
1.4.9STABLE27/09/2020Release notes →
1.4.8STABLE10/08/2020Release notes →
1.4.7STABLE05/07/2020Release notes →
1.4.6STABLE07/06/2020Release notes →
1.4.5STABLE02/06/2020Release notes →
1.4.4STABLE29/04/2020Release notes →

Frequently asked questions

What is the latest version of Roundcube Webmail?
Roundcube Webmail 1.7.3, released 09/08/2026. patchletter checks the vendor's official source daily for new releases.
Where can I find the Roundcube Webmail release notes?
The version history above links to the vendor's official release notes where the vendor publishes them. patchletter deliberately stores no vendor full texts.
How do I get notified about new Roundcube Webmail updates?
Tick Roundcube Webmail off in the catalogue and leave your address. From then on new versions go out by email — one at a time, or bundled in the daily or weekly digest.

An email as soon as a new Roundcube Webmail version ships

We reconcile the vendor source daily. When a new version appears, it lands in your inbox right away or bundled as a digest. The subscription is free and ends with one click.

Watch Roundcube Webmail

Embed this badge

The badge shows the current Roundcube Webmail version and keeps it up to date. Anyone may embed it, no account needed.

Roundcube Webmail badge
[![Roundcube Webmail](https://patchletter.com/badge/roundcube.svg)](https://patchletter.com/en/software/roundcube)
https://patchletter.com/badge/roundcube.svg

Also available: ?v=eol (end of support) and ?v=cve (actively exploited).

Related tools in Collaboration & Communication