Roundcube Webmail 1.5 (LTS)
Roundcube Webmail 1.5 (LTS)
The Roundcube Webmail 1.5 (LTS) reached end of service life on May 10, 2026 — Roundcube Webmail no longer ships security patches or fixes for it. Our third-party support keeps it safe to run: 24/7 engineers manage issues, remediate vulnerabilities, and help you maintain compliance.
24/7 engineers own your Roundcube Webmail 1.5 (LTS) incidents end to end.
Mitigation and patch-around guidance when the vendor no longer ships fixes.
Controls evidence and documentation that keep auditors satisfied.
Specifications
- product
- roundcube
- release
- 1.5
- product Label
- Roundcube Webmail
- release Label
- 1.5 (LTS)
- codename
- lts
- true
- latest Version
- 1.5.15
- release Date
- 2021-10-18
- maintained
- source Url
- https://endoflife.date/roundcube
Lifecycle Dates
- End of Service Life
- May 10, 2026
- Last OEM Support
- Jul 25, 2022
OEM vs. 3rd Party Support
See how third-party support compares to the vendor contract for Roundcube Webmail 1.5 (LTS) — monitoring, break/fix, vulnerability work, operations and compliance, before and after EOSL.
| Feature | OEM Support | 3rd Party Support |
|---|---|---|
| Post-EOSL Support | ||
| Break/Fix Support | Until EOSL | |
| 24/7 Monitoring | ||
| Vulnerability Scanning & Remediation | ||
| Managed Operations | ||
| Procedure & Configuration Review | ||
| Compliance & Audit Documentation | Limited | |
| Discounted Migration to Other Platforms |
Why Choose 3rd Party Support for Roundcube Webmail 1.5 (LTS)?
Vulnerability Remediation
Scanning, mitigation and patch-around guidance for Roundcube Webmail 1.5 (LTS) when the vendor no longer ships fixes.
Compliance Maintenance
Procedure review, controls evidence and the documentation auditors ask for — maintained continuously, not scrambled at audit time.
24/7 Expert Support
Engineers who know this release monitor, manage and fix issues around the clock — break/fix to managed operations.
Roundcube Webmail 1.5 (LTS) Support: Frequently Asked Questions
Is the Roundcube Webmail 1.5 (LTS) still supported?
Roundcube Webmail ended support for the Roundcube Webmail 1.5 (LTS) on May 10, 2026 — no more patches or fixes from the vendor. Third-party support keeps it covered: our engineers manage issues, remediate vulnerabilities, and help you maintain compliance for as long as you run it.
When is the Roundcube Webmail 1.5 (LTS) end of service life (EOSL) date?
Roundcube Webmail lists the end of service life for the Roundcube Webmail 1.5 (LTS) as May 10, 2026.
Can I keep using the Roundcube Webmail 1.5 (LTS) after its EOSL date?
Yes. EOSL means Roundcube Webmail stops issuing patches and support — the software itself keeps running. Third-party support covers it from there: issue management, security vulnerability remediation, and the compliance documentation auditors ask for, for as long as you choose to run it.
How much does third-party support for the Roundcube Webmail 1.5 (LTS) cost?
Typically 40-70% below the OEM maintenance renewal price. Exact pricing depends on quantity, service level and location — request a quote and we respond within 24 hours.
Known Vulnerabilities Affecting Roundcube Webmail 1.5 (LTS)
22 published CVEs affect the Roundcube Webmail 1.5 (LTS), including 7 rated critical or high severity. Roundcube Webmail no longer ships security patches for this release — our engineers provide mitigation guidance, workarounds and hardening support.
| CVE | Severity | CVSS | Published | Summary |
|---|---|---|---|---|
| CVE-2025-49113 | CRITICAL | 9.9 | Jun 2, 2025 | Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP Object Deserialization. |
| CVE-2024-37385 | CRITICAL | 9.8 | Jun 7, 2024 | Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 on Windows allows command injection via im_convert_path and im_identify_path. NOTE: this issue exists because of an incomplete fix for CVE-2020-12641. |
| CVE-2024-42009 | CRITICAL | 9.3 | Aug 5, 2024 | A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a crafted e-mail message that abuses a Desanitization issue in message_body() in program/actions/mail/show.php. |
| CVE-2024-42008 | CRITICAL | 9.3 | Aug 5, 2024 | A Cross-Site Scripting vulnerability in rcmail_action_mail_get->run() in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a malicious e-mail attachment served with a dangerous Content-Type header. |
| CVE-2026-54433 | HIGH | 7.2 | Jul 14, 2026 | In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafted plain-text email message. The attacker-controlled JavaScript executes within the victim's authenticated session simply by opening or previewing the message (zero-click). |
| CVE-2025-68461 | HIGH | 7.2 | Dec 18, 2025 | Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document. |
| CVE-2025-68460 | HIGH | 7.2 | Dec 18, 2025 | Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a information disclosure vulnerability in the HTML style sanitizer. |
| CVE-2026-35539 | MEDIUM | 6.1 | Apr 3, 2026 | An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. XSS exists because of insufficient HTML attachment sanitization in preview mode. A victim must preview a text/html attachment. |
| CVE-2024-37384 | MEDIUM | 6.1 | Jun 7, 2024 | Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via list columns from user preferences. |
| CVE-2024-37383 | MEDIUM | 6.1 | Jun 7, 2024 | Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes. |
| CVE-2023-47272 | MEDIUM | 6.1 | Nov 6, 2023 | Roundcube 1.5.x before 1.5.6 and 1.6.x before 1.6.5 allows XSS via a Content-Type or Content-Disposition header (used for attachment preview or download). |
| CVE-2023-5631 | MEDIUM | 6.1 | Oct 18, 2023 | Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a crafted SVG document because of program/lib/Roundcube/rcube_washtml.php behavior. This could allow a remote attacker to load arbitrary JavaScript code. |
| CVE-2023-43770 | MEDIUM | 6.1 | Sep 22, 2023 | Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of program/lib/Roundcube/rcube_string_replacer.php behavior. |
| CVE-2017-17688 | MEDIUM | 5.9 | May 16, 2018 | The OpenPGP specification allows a Cipher Feedback Mode (CFB) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL. NOTE: third parties report that this is a problem in applications that mishandle the Modification Detection Code (MDC) feature or accept an obsolete packet type, not a problem in the OpenPGP specification |
| CVE-2026-35545 | MEDIUM | 5.3 | Apr 3, 2026 | An issue was discovered in Roundcube Webmail before 1.5.15 and 1.6.15. The remote image blocking feature can be bypassed via SVG content in an e-mail message. This may lead to information disclosure or access-control bypass. This involves the animate element with attributeName=fill/filter/stroke. |
| CVE-2026-35544 | MEDIUM | 5.3 | Apr 3, 2026 | An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to a fixed-position mitigation bypass via the use of !important. |
| CVE-2026-35543 | MEDIUM | 5.3 | Apr 3, 2026 | An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via SVG content (with animate attributes) in an e-mail message. This may lead to information disclosure or access-control bypass. |
| CVE-2026-35542 | MEDIUM | 5.3 | Apr 3, 2026 | An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via a crafted background attribute of a BODY element in an e-mail message. This may lead to information disclosure or access-control bypass. |
| CVE-2005-4368 | MEDIUM | 5.0 | Dec 20, 2005 | roundcube webmail Alpha, with a default high verbose level ($rcmail_config['debug_level'] = 1), allows remote attackers to obtain the full path of the application via an invalid_task parameter, which leaks the path in an error message. |
| CVE-2026-35541 | MEDIUM | 4.2 | Apr 3, 2026 | An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Incorrect password comparison in the password plugin could lead to type confusion that allows a password change without knowing the old password. |
Showing the 20 most severe of 22 known CVEs.
Get Third Party Support