All CVEs
Vulnerability intelligence

CVE-2024-42009

A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a crafted e-mail message that abuses a Desanitization issue in message_body() in program/actions/mail/show.php.

CVSS Score
9.3
Critical
EPSS — Exploit Probability
80%
Riskier than 100% of all CVEs
Exploitation
Confirmed in the wild
KEV since 2025-06-09
Remediation
Patch available
Federal deadline 2025-06-30
NVD entry Vendor patch PoC / advisory CISA KEV

2 articles across 2 outlets · first covered Jul 7, 2026 · latest Jul 13, 2026

Tracked incidents

Associated threat actors

Coverage timeline