The groundhogg plugin before 1.3.5 for WordPress has wp-admin/admin-ajax.php?action=bulkactionlistener remote code execution.
Soundminer – CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Multiple PHP remote file inclusion vulnerabilities in barnraiser AROUNDMe 0.7.7 allow remote attackers to execute arbitrary PHP code via a URL in the (1) languagepathcore parameter to inc/coreprofile.header.php, the (2) templatepathcore parameter to template/barnraiser01/maintcontactview.tpl.php, and the (3) templatepath parameter to template/barnraiser01/default.tpl.php. NOTE: this issue might overlap CVE-2006-5533.
BarnOwl before 1.6.2 does not check the return code of calls to the (1) ZPending and (2) ZReceiveNotice functions in libzephyr, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors.
The WordPress CRM, Email & Marketing Automation for WordPress | Award Winner — Groundhogg WordPress plugin before 2.7.9.4 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admins
PHP remote file inclusion vulnerability in components/core/connect.php in AROUNDMe 1.1 and earlier, when registerglobals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the languagepath parameter.
Roundcube before 1.4.13 and 1.5.x before 1.5.2 allows XSS via an HTML e-mail message with crafted Cascading Style Sheets (CSS) token sequences.
include/iniset.php in Roundcube Webmail 0.5.4 and earlier, when PHP 5.3.7 or 5.3.8 is used, allows remote attackers to trigger a GET request for an arbitrary URL, and cause a denial of service (resource consumption and inbox outage), via a Subject header containing only a URL, a related issue to CVE-2011-3379.
End of life: 7/28/2022, Latest version: 1.3.17
End of life: 7/28/2022, Latest version: 1.3.17
End of life: 10/18/2021, Latest version: 1.2.13
End of life: 10/18/2021, Latest version: 1.2.13
Latest version: 1.1.12
Latest version: 1.1.12
Latest version: 1.0.12
Latest version: 1.0.12
Not associated with Roundcube but didn't see posts about this yet.
On August 4, the Roundcube project released versions 1.6.8 and 1.5.8 (LTS) of their webmail client with fixes for several XSS vulnerabilities in HTML e-mail display. From the announcement page at <https://roundcube.net/news/2024/08/04/security-updates-1.6.8-and-1.5.8>:
Fix XSS vulnerability in post-processing of sanitized HTML content [CVE-2024-42009] Fix XSS vulnerability in serving of attachments other than HTML or SVG [CVE-2024-42008] Fix information leak (access to remote content) via insufficient CSS filtering [CVE-2024-42010]
Links to both releases are on the abovementioned page.
-Valtteri
Hanno Böck je 2. 6. 25 ob 07:26 napisal: Roundcube just published an update that appears to contain an important security fix: https://roundcube.net/news/2025/06/01/security-updates-1.6.11-and-1.5.10
"Fix Post-Auth RCE via PHP Object Deserialization reported by firs0v."
Even though it says "Post-Auth", impact is likely high, as for a webmailer, it is a very common scenario that many people are potentially authenticated. (And it may just be another XSS away from non-authenticated RCE.) I believe this is
https://www.cve.org/CVERecord?id=CVE-2025-49113
CVE-2025-49113 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H score 9.9