Official source evidencegithub.comVersioned article
Official source article · github.com

Release Roundcube Webmail 1.7.3 · roundcube/roundcubemail · GitHub

BlackTree keeps a versioned source snapshot and links it to relevant CVE reports. The publisher remains authoritative for product applicability, release details and installation guidance.

Read the official article ↗
Publishergithub.com
Article IDNo stable ID in source URL
Verified snapshot27 Sept 2026, 20:00 UTC
Linked CVEs10

Linked CVE reports

These are source relationships, not a claim that this article fixes every affected product or branch.

  • CVE-2026-75007Roundcube Webmail: Improper Neutralization of Special Elements used in a Command ('Command Injection')
  • CVE-2026-75003Roundcube Webmail: Incorrect Resource Transfer Between Spheres
  • CVE-2026-75002Roundcube Webmail: Improper Neutralization of Special Elements used in a Command ('Command Injection')
  • CVE-2026-75000Roundcube Webmail: Incorrect Resource Transfer Between Spheres
  • CVE-2026-74998Roundcube Webmail: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
  • CVE-2026-75004In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper rule name quoting could lead to managesieve_disabled_actions setting bypass via a crafted rule name in a Sieve script
  • CVE-2026-74997In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the cmd_learn driver of the markasjunk plugin is subject to remote code execution via crafted placeholder replacement values
  • CVE-2026-74999In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the "Add to address book" action was subject to stored XSS
  • CVE-2026-75010Roundcube Webmail: Incorrect Resource Transfer Between Spheres
  • CVE-2026-75006Roundcube Webmail: Server-Side Request Forgery (SSRF)

Source and provenance

Original title: Release Roundcube Webmail 1.7.3 · roundcube/roundcubemail · GitHub. Captured 27 Sept 2026, 20:00 UTC. The stored article is used for enrichment and change detection; BlackTree does not republish the publisher's full text here.

Open the publisher's current version ↗