RoundcubePlus A.I CyberSecurity Scoring
RoundcubePlus
Company Information
Website:https://roundcubeplus.com
Employees number:5
Number of followers:13
NAICS:5415
Industry Type:IT Services and IT Consulting
Homepage:roundcubeplus.com
RoundcubePlus Risk Score (AI oriented)
Between 750 and 799
RoundcubePlusIT Services and IT Consulting
Updated:
28/05/2026
28/05/2026
756/1000
Fair
Baa
RoundcubePlus Global Score (TPRM)
xxxx
RoundcubePlusIT Services and IT Consulting
Score locked

RoundcubePlusFair
Current Score
756Baa (FAIR)
01000
1 incidents
-1 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
756
MAY 2026
757
Vulnerability
24 May 2026 • RoundcubePlus
Roundcube: Roundcube Webmail Vulnerability Allows Hackers to Execute Malicious SQL Queries
Critical Roundcube Webmail Vulnerabilities Patched in Urgent Security Update
756
CRITICAL-1
ROU1779964080
Critical Roundcube Webmail Vulnerabilities Patched in Urgent Security Update
Roundcube Webmail users must update their systems following the disclosure of multiple severe vulnerabilities, including a critical pre-authentication SQL injection flaw that allows attackers to execute malicious database queries without requiring login credentials. The vulnerabilities were addressed in versions 1.6.16 and 1.7.1, released on May 24, 2026, as part of a high-priority security patch affecting both long-term support and current versions.
The most severe issue a pre-authentication SQL injection in the virtuser_query plugin stems from improper input sanitization due to a preg_replace backslash escape bypass. This flaw enables unauthenticated attackers to inject arbitrary SQL commands, risking unauthorized data access, database manipulation, or privilege escalation. Additional vulnerabilities include:
- A code injection flaw in the LDAP autovalues option, now patched by removing unsafe code evaluation.
- A stored XSS vulnerability in the draft restore dialog’s subject field, allowing HTML/CSS injection.
- A CSS injection bypass via SVG animate elements in the HTML sanitizer.
- An SSRF bypass using crafted local address URLs and a remote resource fetch bypass when blocking external content.
- A pre-auth arbitrary file deletion vulnerability via Redis or Memcache session poisoning.
- A remote image blocking bypass through CSS var() manipulation.
The vulnerabilities were reported by security researchers, including Orange Cyberdefense’s Vulnerability Disclosure Team and independent contributors, underscoring the role of coordinated disclosure in mitigating risks. All Roundcube installations running 1.6.x or 1.7.x are affected, with administrators urged to upgrade immediately to 1.6.16 or 1.7.1 to prevent exploitation. The severity of these flaws particularly the pre-auth SQL injection makes this update critical for organizations using Roundcube, especially in internet-facing environments.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
APRIL 2026
757
MARCH 2026
757
FEBRUARY 2026
757
JANUARY 2026
757
DECEMBER 2025
757
NOVEMBER 2025
757
OCTOBER 2025
757
SEPTEMBER 2025
757
AUGUST 2025
757
JULY 2025
757
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for RoundcubePlus ??
What was RoundcubePlus's A.I Rankiteo Cyber Score in May 2026 ??
What was RoundcubePlus's A.I Rankiteo Cyber Score in April 2026 ??
What was RoundcubePlus's A.I Rankiteo Cyber Score in March 2026 ??
What was RoundcubePlus's A.I Rankiteo Cyber Score in February 2026 ??
What was RoundcubePlus's A.I Rankiteo Cyber Score in January 2026 ??
What was RoundcubePlus's A.I Rankiteo Cyber Score in December 2025 ??
What was RoundcubePlus's A.I Rankiteo Cyber Score in November 2025 ??
What was RoundcubePlus's A.I Rankiteo Cyber Score in October 2025 ??
What was RoundcubePlus's A.I Rankiteo Cyber Score in September 2025 ??
What was RoundcubePlus's A.I Rankiteo Cyber Score in August 2025 ??
What was RoundcubePlus's A.I Rankiteo Cyber Score in July 2025 ??
What is the average per-incident point impact on RoundcubePlus's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with RoundcubePlus ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view RoundcubePlus's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?