{"api_version":"v1","generated_at":"2026-10-05T15:40:00+00:00","product":{"cve_count":40,"evidence_gap_note":"This CVE identity is linked to an existing Lifecycle product history.","id":"security:cve-roundcube-webmail-bbabb8a9eab7","lifecycle_state":"covered","linked_lifecycle_url":"https://lifecycle.blacktree.nl/targets/roundcube","name":"webmail","next_cursor":null,"observations":[{"affected":"1.6.0 < 1.6.18; 1.7.0 < 1.7.3","affected_versions_present":true,"cve_id":"CVE-2026-75010","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-75010","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-08-17T14:11:00.263Z","patch_url":"https://roundcube.net/news/2026/08/09/security-updates-1.6.18-and-1.7.3","primary_source":"","published":"2026-08-17T13:01:26.692Z"},{"affected":"1.6.0 < 1.6.18; 1.7.0 < 1.7.3","affected_versions_present":true,"cve_id":"CVE-2026-75007","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-75007","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-08-18T03:55:32.206Z","patch_url":"https://roundcube.net/news/2026/08/09/security-updates-1.6.18-and-1.7.3","primary_source":"","published":"2026-08-17T12:58:48.792Z"},{"affected":"1.6.0 < 1.6.18; 1.7.0 < 1.7.3","affected_versions_present":true,"cve_id":"CVE-2026-75006","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-75006","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-08-17T14:06:46.947Z","patch_url":"https://roundcube.net/news/2026/08/09/security-updates-1.6.18-and-1.7.3","primary_source":"","published":"2026-08-17T12:56:47.427Z"},{"affected":"1.6.0 < 1.6.18; 1.7.0 < 1.7.3","affected_versions_present":true,"cve_id":"CVE-2026-75004","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-75004","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-08-17T14:37:04.784Z","patch_url":"https://roundcube.net/news/2026/08/09/security-updates-1.6.18-and-1.7.3","primary_source":"","published":"2026-08-17T12:53:50.097Z"},{"affected":"1.6.0 < 1.6.18; 1.7.0 < 1.7.3","affected_versions_present":true,"cve_id":"CVE-2026-75003","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-75003","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-08-18T03:55:30.789Z","patch_url":"https://roundcube.net/news/2026/08/09/security-updates-1.6.18-and-1.7.3","primary_source":"","published":"2026-08-17T12:50:51.836Z"},{"affected":"1.6.0 < 1.6.18; 1.7.0 < 1.7.3","affected_versions_present":true,"cve_id":"CVE-2026-75002","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-75002","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-08-18T03:55:29.235Z","patch_url":"https://roundcube.net/news/2026/08/09/security-updates-1.6.18-and-1.7.3","primary_source":"","published":"2026-08-17T12:48:41.254Z"},{"affected":"1.6.0 < 1.6.18; 1.7.0 < 1.7.3","affected_versions_present":true,"cve_id":"CVE-2026-75000","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-75000","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-08-18T03:55:27.932Z","patch_url":"https://roundcube.net/news/2026/08/09/security-updates-1.6.18-and-1.7.3","primary_source":"","published":"2026-08-17T12:45:56.860Z"},{"affected":"1.6.0 < 1.6.18; 1.7.0 < 1.7.3","affected_versions_present":true,"cve_id":"CVE-2026-74999","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-74999","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-08-17T14:33:47.482Z","patch_url":"https://roundcube.net/news/2026/08/09/security-updates-1.6.18-and-1.7.3","primary_source":"","published":"2026-08-17T12:42:51.526Z"},{"affected":"1.6.0 < 1.6.18; 1.7.0 < 1.7.3","affected_versions_present":true,"cve_id":"CVE-2026-74998","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-74998","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-08-17T16:01:16.269Z","patch_url":"https://roundcube.net/news/2026/08/09/security-updates-1.6.18-and-1.7.3","primary_source":"","published":"2026-08-17T12:40:29.903Z"},{"affected":"1.6.0 < 1.6.18; 1.7.0 < 1.7.3","affected_versions_present":true,"cve_id":"CVE-2026-74997","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-74997","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-08-17T14:34:26.557Z","patch_url":"https://roundcube.net/news/2026/08/09/security-updates-1.6.18-and-1.7.3","primary_source":"","published":"2026-08-17T12:37:45.126Z"},{"affected":"1.6.0 < 1.6.17; 1.7.0 < 1.7.2","affected_versions_present":true,"cve_id":"CVE-2026-54432","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-54432","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-07-15T15:13:14.654Z","patch_url":"","primary_source":"","published":"2026-07-14T16:21:55.409Z"},{"affected":"1.6.0 < 1.6.17; 1.7.0 < 1.7.2","affected_versions_present":true,"cve_id":"CVE-2026-54433","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-54433","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-07-15T14:10:33.042Z","patch_url":"https://roundcube.net/news/2026/07/05/security-updates-1.6.17-and-1.7.2","primary_source":"","published":"2026-07-14T16:18:16.549Z"},{"affected":"1.6.0 < 1.6.17; 1.7.0 < 1.7.2","affected_versions_present":true,"cve_id":"CVE-2026-62644","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-62644","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-07-14T17:15:20.139Z","patch_url":"https://roundcube.net/news/2026/07/05/security-updates-1.6.17-and-1.7.2","primary_source":"","published":"2026-07-14T15:55:22.925Z"},{"affected":"1.6.0 < 1.6.17; 1.7.0 < 1.7.2","affected_versions_present":true,"cve_id":"CVE-2026-62643","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-62643","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-07-14T17:17:16.894Z","patch_url":"https://roundcube.net/news/2026/07/05/security-updates-1.6.17-and-1.7.2","primary_source":"","published":"2026-07-14T15:51:46.996Z"},{"affected":"1.6.0 < 1.6.17; 1.7.0 < 1.7.2","affected_versions_present":true,"cve_id":"CVE-2026-62642","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-62642","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-07-14T17:18:18.192Z","patch_url":"https://roundcube.net/news/2026/07/05/security-updates-1.6.17-and-1.7.2","primary_source":"","published":"2026-07-14T15:49:17.798Z"},{"affected":"1.6.0 < 1.6.17; 1.7.0 < 1.7.2","affected_versions_present":true,"cve_id":"CVE-2026-62641","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-62641","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-07-14T17:27:50.013Z","patch_url":"https://roundcube.net/news/2026/07/05/security-updates-1.6.17-and-1.7.2","primary_source":"","published":"2026-07-14T15:46:29.138Z"},{"affected":"1.6.0 < 1.6.16; 1.7.0 < 1.7.1","affected_versions_present":true,"cve_id":"CVE-2026-48849","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-48849","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-26T13:01:11.210Z","patch_url":"","primary_source":"","published":"2026-05-25T19:30:38.414Z"},{"affected":"1.6.0 < 1.6.16; 1.7.0 < 1.7.1","affected_versions_present":true,"cve_id":"CVE-2026-48848","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-48848","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-26T13:00:52.631Z","patch_url":"","primary_source":"","published":"2026-05-25T19:27:54.841Z"},{"affected":"1.6.0 < 1.6.16; 1.7.0 < 1.7.1","affected_versions_present":true,"cve_id":"CVE-2026-48847","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-48847","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-26T13:02:10.123Z","patch_url":"","primary_source":"","published":"2026-05-25T19:23:40.853Z"},{"affected":"1.6.0 < 1.6.16; 1.7.0 < 1.7.1","affected_versions_present":true,"cve_id":"CVE-2026-48846","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-48846","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-26T13:05:56.818Z","patch_url":"","primary_source":"","published":"2026-05-25T19:21:09.656Z"},{"affected":"1.6.14 < 1.6.16; 1.7.0 < 1.7.1","affected_versions_present":true,"cve_id":"CVE-2026-48845","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-48845","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-27T03:55:26.292Z","patch_url":"","primary_source":"","published":"2026-05-25T19:18:09.549Z"},{"affected":"1.6.0 < 1.6.16; 1.7.0 < 1.7.1","affected_versions_present":true,"cve_id":"CVE-2026-48844","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-48844","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-26T12:48:17.535Z","patch_url":"","primary_source":"","published":"2026-05-25T19:14:48.753Z"},{"affected":"1.6.14 < 1.6.16; 1.7.0 < 1.7.1","affected_versions_present":true,"cve_id":"CVE-2026-48843","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-48843","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-26T12:50:42.557Z","patch_url":"","primary_source":"","published":"2026-05-25T19:11:04.351Z"},{"affected":"Webmail: 1.6.0 < 1.6.16, 1.7.0 < 1.7.1","affected_versions_present":true,"cve_id":"CVE-2026-48842","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-48842","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-25T03:55:21.992Z","patch_url":"https://www.cyber.gc.ca/en/alerts-advisories/roundcube-security-advisory-av26-503","primary_source":"","published":"2026-05-25T19:06:37.434Z"},{"affected":"< 1.5.15; 1.6.0 < 1.6.15","affected_versions_present":true,"cve_id":"CVE-2026-35545","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-35545","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-04-03T15:36:13.062Z","patch_url":"https://roundcube.net/news/2026/03/29/security-updates-1.7-rc6-1.6.15-1.5.15","primary_source":"","published":"2026-04-03T04:02:06.765Z"},{"affected":"< 1.5.14; 1.6.0 < 1.6.14","affected_versions_present":true,"cve_id":"CVE-2026-35544","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-35544","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-04-03T12:50:12.338Z","patch_url":"https://roundcube.net/news/2026/03/18/security-updates-1.7-rc5-1.6.14-1.5.14","primary_source":"","published":"2026-04-03T03:59:49.053Z"},{"affected":"< 1.5.14; 1.6.0 < 1.6.14","affected_versions_present":true,"cve_id":"CVE-2026-35543","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-35543","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-04-03T12:50:54.031Z","patch_url":"https://roundcube.net/news/2026/03/18/security-updates-1.7-rc5-1.6.14-1.5.14","primary_source":"","published":"2026-04-03T03:57:06.528Z"},{"affected":"< 1.5.14; 1.6.0 < 1.6.14","affected_versions_present":true,"cve_id":"CVE-2026-35542","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-35542","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-04-03T12:51:27.986Z","patch_url":"https://roundcube.net/news/2026/03/18/security-updates-1.7-rc5-1.6.14-1.5.14","primary_source":"","published":"2026-04-03T03:54:18.465Z"},{"affected":"< 1.5.14; 1.6.0 < 1.6.14","affected_versions_present":true,"cve_id":"CVE-2026-35541","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-35541","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-04-03T12:52:08.638Z","patch_url":"https://roundcube.net/news/2026/03/18/security-updates-1.7-rc5-1.6.14-1.5.14","primary_source":"","published":"2026-04-03T03:50:47.422Z"},{"affected":"1.6.0 < 1.6.14","affected_versions_present":true,"cve_id":"CVE-2026-35540","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-35540","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-04-03T12:52:38.240Z","patch_url":"https://roundcube.net/news/2026/03/18/security-updates-1.7-rc5-1.6.14-1.5.14","primary_source":"","published":"2026-04-03T03:47:51.456Z"},{"affected":"< 1.5.14; 1.6.0 < 1.6.14","affected_versions_present":true,"cve_id":"CVE-2026-35539","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-35539","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-04-03T13:10:55.717Z","patch_url":"https://roundcube.net/news/2026/03/18/security-updates-1.7-rc5-1.6.14-1.5.14","primary_source":"","published":"2026-04-03T03:39:17.400Z"},{"affected":"< 1.5.14; 1.6.0 < 1.6.14","affected_versions_present":true,"cve_id":"CVE-2026-35538","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-35538","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-04-03T13:11:22.365Z","patch_url":"https://roundcube.net/news/2026/03/18/security-updates-1.7-rc5-1.6.14-1.5.14","primary_source":"","published":"2026-04-03T03:35:36.925Z"},{"affected":"< 1.5.14; 1.6.0 < 1.6.14","affected_versions_present":true,"cve_id":"CVE-2026-35537","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-35537","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-04-11T14:12:39.387Z","patch_url":"https://github.com/roundcube/roundcubemail/commit/6d586cfa4d8a31f7957f7a445aaedd52592a0e74","primary_source":"","published":"2026-04-03T03:28:29.321Z"},{"affected":"< 1.5.13; 1.6.0 < 1.6.13","affected_versions_present":true,"cve_id":"CVE-2026-26079","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-26079","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-02-11T16:06:28.336Z","patch_url":"","primary_source":"","published":"2026-02-11T04:27:24.156Z"},{"affected":"< 1.5.13; 1.6.0 < 1.6.13","affected_versions_present":true,"cve_id":"CVE-2026-25916","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-25916","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-02-09T15:05:40.859Z","patch_url":"","primary_source":"","published":"2026-02-09T08:14:10.177Z"},{"affected":"Webmail: < 1.5.12, 1.6.0 < 1.6.12","affected_versions_present":true,"cve_id":"CVE-2025-68461","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-68461","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-10-01T18:12:05.532Z","patch_url":"https://roundcube.net/news/2025/12/13/security-updates-1.6.12-and-1.5.12","primary_source":"","published":"2025-12-18T05:00:54.423Z"},{"affected":"< 1.5.12; 1.6.0 < 1.6.12","affected_versions_present":true,"cve_id":"CVE-2025-68460","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-68460","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-12-18T18:53:53.491Z","patch_url":"https://roundcube.net/news/2025/12/13/security-updates-1.6.12-and-1.5.12","primary_source":"","published":"2025-12-18T04:54:13.338Z"},{"affected":"Webmail: < 1.5.10, 1.6.0 < 1.6.11","affected_versions_present":true,"cve_id":"CVE-2025-49113","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-49113","fixed":"The Cyber Centre strongly recommends that organizations update to Roundcube Webmail versions 1.5.10+ or 1.6.11+ Footnote 2 , which would mitigate issues reported by both CVEs mentioned here (CVE-2024-42009 and CVE-2025-49113). The Cyber Centre recommends that organizations: Assess the installation of Roundcube Webmail. Apply updates to Roundcube Webmail without delay. Monitor affected systems for signs of exploitation. Monitor for brute-force attempts and if possible, implement rate limitation techniques. In addition, the Cyber Centre strongly recommends that organizations review and implement the Cyber Centre's Top 10 IT Security Actions Footnote 6 with an emphasis on the following strategies: If activity matching the content of this alert is discovered, recipients are encouraged to report via the My Cyber Portal , or email contact@cyber.gc.ca .","last_modified":"2026-02-21T04:56:23.141Z","patch_url":"https://www.cyber.gc.ca/en/alerts-advisories/vulnerability-impacting-roundcube-webmail-cve-2025-49113","primary_source":"","published":"2025-06-02T00:00:00.000Z"},{"affected":"n/a","affected_versions_present":true,"cve_id":"CVE-2024-42009","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-42009","fixed":"The Cyber Centre strongly recommends that organizations update to Roundcube Webmail versions 1.5.10+ or 1.6.11+ Footnote 2 , which would mitigate issues reported by both CVEs mentioned here (CVE-2024-42009 and CVE-2025-49113). The Cyber Centre recommends that organizations: Assess the installation of Roundcube Webmail. Apply updates to Roundcube Webmail without delay. Monitor affected systems for signs of exploitation. Monitor for brute-force attempts and if possible, implement rate limitation techniques. In addition, the Cyber Centre strongly recommends that organizations review and implement the Cyber Centre's Top 10 IT Security Actions Footnote 6 with an emphasis on the following strategies: If activity matching the content of this alert is discovered, recipients are encouraged to report via the My Cyber Portal , or email contact@cyber.gc.ca .","last_modified":"2025-10-21T22:55:48.964Z","patch_url":"https://www.cyber.gc.ca/en/alerts-advisories/vulnerability-impacting-roundcube-webmail-cve-2025-49113","primary_source":"","published":"2024-08-05T00:00:00.000Z"},{"affected":"webmail: < 1.5.7, 1.6.0 < 1.6.7","affected_versions_present":true,"cve_id":"CVE-2024-37383","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-37383","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-10-21T23:05:16.615Z","patch_url":"https://github.com/roundcube/roundcubemail/commit/43aaaa528646877789ec028d87924ba1accf5242","primary_source":"","published":"2024-06-07T00:00:00.000Z"},{"affected":"Roundcubemail: 1.6.0 < 1.6.3, 1.5.0 < 1.5.4, 1.4.0 < 1.5.14","affected_versions_present":true,"cve_id":"CVE-2023-5631","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-5631","fixed":"Roundcubemail: 1.6.4, 1.5.5, 1.5.15","last_modified":"2025-10-21T23:05:34.074Z","patch_url":"https://github.com/roundcube/roundcubemail/commit/6ee6e7ae301e165e2b2cb703edf75552e5376613","primary_source":"","published":"2023-10-18T14:51:18.443Z"},{"affected":"webmail: < 1.4.14, 1.5.0 < 1.5.4, 1.6.0 < 1.6.3; debian linux: 10","affected_versions_present":true,"cve_id":"CVE-2023-43770","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-43770","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-10-21T23:05:36.969Z","patch_url":"https://github.com/roundcube/roundcubemail/commit/e92ec206a886461245e1672d8530cc93c618a49b","primary_source":"","published":"2023-09-22T00:00:00.000Z"},{"affected":"webmail: < 1.3.12, 1.4.0 < 1.4.5","affected_versions_present":true,"cve_id":"CVE-2020-13965","cve_url":"https://cve.blacktree.nl/cve/CVE-2020-13965","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-10-21T23:35:42.715Z","patch_url":"https://github.com/roundcube/roundcubemail/commit/884eb611627ef2bd5a2e20e02009ebb1eceecdc3","primary_source":"","published":"2020-06-09T02:45:24.000Z"}],"source_generated_at":"2026-10-05T06:20:29.126Z","vendor":"roundcube"}}
