Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
RoundcubePlus

RoundcubePlus Vendor Cyber Rating & Cyber Score

roundcubeplus.com

Tecorama redefines the Roundcube webmail experience. We're driven to supercharge Roundcube webmail, blending it with vibrant themed skins and cutting-edge productivity plugins; including 2FA, email signature generator, Nextcloud, dropbox, google drive integration and more...


RoundcubePlus A.I CyberSecurity Scoring

RoundcubePlus
Company Information
Website:https://roundcubeplus.com
Employees number:5
Number of followers:13
NAICS:5415
Industry Type:IT Services and IT Consulting
Homepage:roundcubeplus.com
RoundcubePlus Risk Score (AI oriented)
Between 750 and 799
logo
RoundcubePlusIT Services and IT Consulting
Updated:
28/05/2026
756/1000
Fair
Baa
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
RoundcubePlus Global Score (TPRM)
xxxx
logo
RoundcubePlusIT Services and IT Consulting
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

RoundcubePlus
RoundcubePlusFair
Current Score
756Baa (FAIR)
01000
1 incidents
-1 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
756Before Incident
MAY 2026
757Before Incident
Vulnerability
24 May 2026RoundcubePlus
Roundcube: Roundcube Webmail Vulnerability Allows Hackers to Execute Malicious SQL Queries

Critical Roundcube Webmail Vulnerabilities Patched in Urgent Security Update

756After Incident
CRITICAL-1
ROU1779964080
Critical Roundcube Webmail Vulnerabilities Patched in Urgent Security Update Roundcube Webmail users must update their systems following the disclosure of multiple severe vulnerabilities, including a critical pre-authentication SQL injection flaw that allows attackers to execute malicious database queries without requiring login credentials. The vulnerabilities were addressed in versions 1.6.16 and 1.7.1, released on May 24, 2026, as part of a high-priority security patch affecting both long-term support and current versions. The most severe issue a pre-authentication SQL injection in the virtuser_query plugin stems from improper input sanitization due to a preg_replace backslash escape bypass. This flaw enables unauthenticated attackers to inject arbitrary SQL commands, risking unauthorized data access, database manipulation, or privilege escalation. Additional vulnerabilities include: - A code injection flaw in the LDAP autovalues option, now patched by removing unsafe code evaluation. - A stored XSS vulnerability in the draft restore dialog’s subject field, allowing HTML/CSS injection. - A CSS injection bypass via SVG animate elements in the HTML sanitizer. - An SSRF bypass using crafted local address URLs and a remote resource fetch bypass when blocking external content. - A pre-auth arbitrary file deletion vulnerability via Redis or Memcache session poisoning. - A remote image blocking bypass through CSS var() manipulation. The vulnerabilities were reported by security researchers, including Orange Cyberdefense’s Vulnerability Disclosure Team and independent contributors, underscoring the role of coordinated disclosure in mitigating risks. All Roundcube installations running 1.6.x or 1.7.x are affected, with administrators urged to upgrade immediately to 1.6.16 or 1.7.1 to prevent exploitation. The severity of these flaws particularly the pre-auth SQL injection makes this update critical for organizations using Roundcube, especially in internet-facing environments.
INCIDENT DETAILS -
TYPE
SQL InjectionCode InjectionStored XSSCSS InjectionSSRF BypassArbitrary File DeletionRemote Resource Fetch Bypass
IMPACT
Data Compromised: Unauthorized data access, database manipulation, or privilege escalationSystems Affected: Roundcube Webmail installations (versions 1.6.x and 1.7.x)
DATA BREACH
Sensitivity Of Data: Potentially sensitive database contents (e.g., user credentials, emails)
APRIL 2026
757Before Incident
MARCH 2026
757Before Incident
FEBRUARY 2026
757Before Incident
JANUARY 2026
757Before Incident
DECEMBER 2025
757Before Incident
NOVEMBER 2025
757Before Incident
OCTOBER 2025
757Before Incident
SEPTEMBER 2025
757Before Incident
AUGUST 2025
757Before Incident
JULY 2025
757Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for RoundcubePlus ?
?
What was RoundcubePlus's A.I Rankiteo Cyber Score in May 2026 ?
?
What was RoundcubePlus's A.I Rankiteo Cyber Score in April 2026 ?
?
What was RoundcubePlus's A.I Rankiteo Cyber Score in March 2026 ?
?
What was RoundcubePlus's A.I Rankiteo Cyber Score in February 2026 ?
?
What was RoundcubePlus's A.I Rankiteo Cyber Score in January 2026 ?
?
What was RoundcubePlus's A.I Rankiteo Cyber Score in December 2025 ?
?
What was RoundcubePlus's A.I Rankiteo Cyber Score in November 2025 ?
?
What was RoundcubePlus's A.I Rankiteo Cyber Score in October 2025 ?
?
What was RoundcubePlus's A.I Rankiteo Cyber Score in September 2025 ?
?
What was RoundcubePlus's A.I Rankiteo Cyber Score in August 2025 ?
?
What was RoundcubePlus's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on RoundcubePlus's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with RoundcubePlus ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view RoundcubePlus's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?