Fact-checked by Grok 2 weeks ago

Roundcube


Roundcube is a free and open-source web-based IMAP that offers a browser-accessible interface resembling desktop email applications.
Originally developed by Thomas Bruederli as a personal project in 2005, it reached its first stable release in early 2008 after two years of development.
Key features include drag-and-drop message management, full and message support, threaded listings, spell checking, multi-language capabilities supporting over 70 languages, and an integrated with search functionality.
Licensed under the version 3 or later, Roundcube emphasizes security, extensibility via plugins, and resource efficiency, making it suitable for on-premise deployments.
In November 2023, the project was acquired by to sustain its open-source development amid challenges like a prior supply-chain compromise, ensuring ongoing updates such as support for 8.1 and beyond in recent versions.

History and Development

Inception and Founding

Roundcube was initiated in July 2005 by Swiss software engineer Thomas Bruederli as a personal open-source side project to address the shortcomings of existing webmail clients, which at the time offered limited interfaces confined to basic formatted text without leveraging emerging browser capabilities. Bruederli, driven by a passion for free software and the potential of asynchronous web technologies like AJAX, aimed to develop a standards-compliant IMAP client with a responsive, desktop-like user interface that could operate on standard LAMPP server setups. This effort responded to the absence of modern, freely available alternatives, positioning Roundcube as a browser-based solution emphasizing seamless email access and manipulation without full page reloads. The project's early prototypes focused on core IMAP protocol integration, drawing from open-source libraries such as those from IlohaMail for email handling and incorporating features like support and folder management from the outset. The first public alpha release, designated 0.1-20051007, occurred on October 7, 2005, marking the initial announcement to developers via mailing lists and highlighting improvements in and multilingual capabilities. Development in these formative years remained largely a solo endeavor by Bruederli, without a predefined , allowing the project to evolve organically through iterative enhancements before broader contributions began to accelerate around 2007, coinciding with growing interest in AJAX-driven applications.

Major Releases and Milestones

The stable version 1.0.0 of Roundcube Webmail was released on April 7, 2014, transitioning from the prior 0.x series to semantic versioning (1.x) and establishing a mature codebase after years of development. This milestone introduced a centralized repository for easier discovery and updates, streamlined into a single file, advanced LDAP features, and capabilities like importing messages with attachments during composition and toggling between and plaintext views. Version 1.3.0 followed on June 26, 2017, enhancing core functionality with improved message search, threading displays, and PDF preview support, alongside refinements to the plugin for better extensibility. Subsequent minor updates in the 1.3 series, maintained as a branch until around 2020, focused on bug fixes and security patches to sustain deployments. A significant advancement came with version 1.4.0 on November 9, 2019, which debuted the skin as Roundcube's inaugural responsive design, optimizing layout for desktops, tablets, and mobile devices through adaptive CSS and LESS customization options. The adoption of explicit (LTS) practices solidified in the 1.5 series, launched October 18, 2021, with extended updates for production reliability, including 8 compatibility and ongoing releases up to 1.5.11 in June 2025. Version 1.6.0, released July 25, 2022, further emphasized performance optimizations and modern support (up to 8.3), with maintenance continuing through 1.6.11 in June 2025 to address vulnerabilities like CVE-2025-49113. As of October 2025, the project advances toward 1.7, with beta 2 issued on October 1, incorporating breaking changes such as updated dependencies and new extensibility hooks while deprecating older versions.

Community Governance and Funding

Roundcube has been governed as an independent open-source project by a core team of volunteer developers, with decision-making primarily conducted through mailing lists and, following the migration of its issue tracker from to on March 20, 2016, via issues and pull requests. The project's structure emphasizes community input, with plugins often developed and maintained separately by individual contributors rather than the core team. This volunteer-led model has sustained development since its inception, though it has resulted in dependency on ad-hoc participation, contributing to extended timelines for addressing issues. Funding for Roundcube historically relied on voluntary donations and sporadic efforts, without significant corporate sponsorship. A notable 2015 Indiegogo campaign for "Roundcube Next," aimed at refactoring the core codebase, raised over $100,000 but ultimately failed to deliver promised updates, highlighting challenges in volunteer-driven and leading to perceptions of stalled progress. The absence of dedicated backing exacerbated slower patch cycles, as maintenance depended on the availability of a small group of lead developers. In November 2023, assumed stewardship of Roundcube, committing to invest resources for accelerated development while preserving its independence as a standalone project. This shift integrates Roundcube into 's ecosystem, which supports open-source initiatives through a combination of community donations, enterprise subscriptions, and direct investments, enabling hiring and community expansion to address prior limitations. The arrangement maintains open governance principles, with ongoing community contributions welcomed via established channels.

Technical Architecture

Core Technologies and Protocols

Roundcube is developed using as its primary programming language, with a minimum requirement of version 7.3 to execute server-side scripts for processing -related tasks. The backend architecture centers on PHP modules that interface directly with email protocols and manage data persistence, ensuring stateless operation between HTTP requests by leveraging database-backed sessions. For data storage, Roundcube utilizes relational databases including , , , , or alternatives like MSSQL and , primarily to maintain user-specific elements such as sessions, settings, address books, and message caches, while deferring bulk storage to remote servers. This separation enables efficient handling of transient without duplicating full mailboxes locally. The core protocols are IMAP (supporting IMAP4rev1 and extensions for secure connections) for fetching, searching, and manipulating emails on remote servers, and SMTP for outbound message transmission, with compatibility for IDNA internationalization and SMTPUTF8 for non-ASCII content. These standards ensure interoperability with standard mail infrastructure, as PHP-based connectors abstract the protocol negotiations and error handling. Modularity is achieved through dependency injection via Composer for managing external PHP libraries, a shift from earlier reliance on PEAR packages implemented around version 1.6 to streamline installation and updates of components like authentication handlers and protocol wrappers. Roundcube is licensed under the GNU General Public License version 3 or later, which mandates that modifications and distributions remain open-source, though exceptions apply to ancillary elements such as skins and plugins to encourage community contributions without imposing the full GPL constraints on those.

User Interface Design

Roundcube features an AJAX-driven user interface structured as a , delivering desktop-like responsiveness in a environment. This design facilitates dynamic elements such as message list updates and inline composition without full page reloads, enhancing operational fluidity. Drag-and-drop functionality for attachments, introduced in version 1.2.0 on May 22, 2016, and threaded conversation views for grouping related messages further mimic native client behaviors. The "" theme, released alongside version 1.4.0, provides responsive layouts adapting to desktops, tablets, and devices, prioritizing usability across screen sizes. This rendering approach supports access but relies heavily on , which has been criticized for introducing dependencies vulnerable to exploitation. Localization extends to over 80 languages, configurable via user preferences for global . navigation ensures core elements receive tab focus and support mouse-free operation, aligning with development guidelines emphasizing operable interfaces.

Features and Functionality

Essential Email Operations

Roundcube enables core email operations by interfacing directly with servers to access and manipulate message stores in folders such as Inbox, Sent, and Drafts. Users can select messages for deletion, marking as read or unread, and moving between folders using standard IMAP commands, ensuring synchronization with the server without local caching dependencies. Composing new messages occurs through a dedicated where users input recipient addresses—either typed directly or autocompleted from the —along with a subject line and text composed in plain text or format via an integrated editor. Attachments are added by uploading files from the local system, with Roundcube encoding them using multipart structures to support multimedia elements like images and documents during transmission via SMTP. The system enforces basic validation, such as required fields, before queuing the message for sending. Replying to or forwarding messages populates the compose form with relevant details: reply includes the original sender in the To field and quotes the prior content; reply-all extends recipients to include all original addresses; forwarding attaches the message as an enclosure or inlines it per user preference, preserving parts for attachments. These actions leverage IMAP fetch to retrieve full message data, including headers and body, for accurate reconstruction. Searching functionality utilizes IMAP's native search extensions, allowing queries by , recipient, , content, date ranges, or flags across specified folders or globally. Results display in a paginated list with previews, supporting quick filters for recent or unread items, and integrates with folder navigation for refined operations like bulk actions on matches. The integrated stores contacts in a SQL backend by default, with optional LDAP synchronization for , enabling addition, editing, or deletion of entries including names, email addresses, and phone numbers. Users can create groups for bulk selection during composition and import/export contacts in formats like or for portability. Basic filtering rules apply client-side sorting based on headers or matches, directing messages to folders or applying flags upon , though advanced server-side rules require separate configuration. MIME decoding ensures proper rendering of received attachments and mixed- emails, displaying inline where possible or offering download options.

Extensibility and Customization

Roundcube employs a Plugin that facilitates extensions to its core functionality through modular hooks and callbacks, allowing developers to add features such as custom authentication, UI modifications, and integrations without altering the base codebase. The includes methods like init() for initialization, add_hook() for event interception, and register_action() for handling custom requests, enabling plugins to inject , override templates, or process server-side logic early in the session lifecycle. This architecture supports integrations like two-factor authentication plugins that hook into login processes and plugins for PGP encryption handling via dedicated actions. Plugins are managed via , requiring addition to a composer.json file followed by execution of php composer.phar install in the Roundcube , which places them in the plugins/ folder; activation occurs by appending plugin names to the $config['plugins'] array in config/config.inc.php. Community and third-party , available through the official repository on Packagist, cover functionalities such as filter management for server-side rules and PDF exports for message archiving. Customization extends to user interface theming via a dedicated skin system, comprising templates with dynamic <roundcube: .../> tags and accompanying CSS stylesheets stored in skins/<skinname>/ directories. Developers can override specific templates (e.g., login.html or mail.html) or extend base skins like "" by defining inheritance in meta.json and selectively modifying CSS for branding, such as incorporating provider logos or adjusting color schemes. This template-driven approach, combined with the plugin API's template handlers, permits hosting providers to tailor interfaces for visual consistency and alignment.

Security Record

Evolution of Vulnerabilities

Roundcube's early versions, such as 0.2.2 released around 2008, suffered from (CSRF) vulnerabilities like CVE-2009-4076, which allowed attackers to hijack user sessions through forged requests lacking proper token validation. These initial flaws arose from foundational oversights in request authentication, common in nascent PHP-based web applications with limited formal security reviews. Subsequent releases in the 0.x and early 1.x series perpetuated similar patterns, with CSRF recurring in CVE-2014-9587 affecting versions before 1.0.4 due to multiple unprotected endpoints. As the 1.x branch matured from 2013 onward, (XSS) emerged as a dominant issue, driven by insufficient sanitization of user inputs in rendering and attachments; for instance, versions up to 1.3.x exhibited stored XSS via unsanitized , escalating to persistent variants in later 1.4.x and 1.5.x releases. This trend reflected reactive development where community-reported exploits prompted fixes, but incomplete coverage of edge cases in string handling allowed persistence, with over 25 XSS-related CVEs documented by 2024. Input validation gaps, such as inadequate escaping in or attachment processing, compounded risks in -centric workflows. Deeper systemic issues surfaced in session and data handling, with PHP deserialization flaws tracing to legacy code patterns introduced in early PHP integrations; a prominent example involved untrusted data in URL parameters persisting undetected for approximately a , enabling object injection leading to execution. CSRF themes echoed this, as in CVE-2020-12626 before 1.4.4, where POST request distinctions were overlooked in logout mechanisms, underscoring challenges in refactoring inherited without comprehensive rewrites. Volunteer-led auditing, inherent to the open-source model, favored ad-hoc community disclosures over proactive scans, fostering cycles of rediscovery in under-resourced areas like third-party dependencies. Dependencies amplified exposure, with libraries like phpseclib introducing risks such as CVE-2024-27354, a denial-of-service vector from inefficient primality checks in certificate validation, affecting Roundcube's cryptographic operations without native mitigations. Cumulatively, these patterns yielded at least 37 CVEs since , with XSS comprising the majority and code execution instances rising in later years, illustrating tensions between feature evolution and security hardening in a volunteer-maintained reliant on PHP's evolving ecosystem.

Response Mechanisms and Recent Fixes

On June 1, 2025, the Roundcube project released versions 1.6.11 and 1.5.10 to address CVE-2025-49113, a post-authentication remote code execution vulnerability stemming from insufficient restrictions on the _from parameter in URLs, enabling PHP object deserialization by authenticated users. This flaw affected versions prior to 1.5.10 and 1.6.0 through 1.6.10, with exploitation observed in the wild, including the June 2025 breach of the Cock.li email service where over 1 million user records were compromised due to unpatched Roundcube instances. The U.S. (CISA) added CVE-2025-49113 to its Known Exploited Vulnerabilities catalog on June 9, 2025, based on evidence of active , and directed agencies to apply mitigations by June 30, 2025, emphasizing immediate patching to systems. Roundcube's response process relies primarily on community-reported issues channeled through security advisories published on its official site, without a formal , which has contributed to delays in vulnerability disclosures and patches compared to incentivized models. In LTS branches like 1.5.x, patch deployment has faced persistent delays attributable to limited maintainer resources, as the project depends on volunteer contributions for and verification, though core releases incorporate enhanced practices post-2020 to accelerate fixes for critical issues. This volunteer-driven model, while enabling rapid advisory issuance for confirmed exploits, underscores bandwidth constraints in maintaining backported updates across supported versions.

Adoption and Reception

Deployment Statistics and Integrations

Roundcube is widely deployed as an open-source solution, particularly in hosting environments where it serves as the default client in popular control panels. It is bundled by default in , a leading used across millions of domains, enabling seamless access for users in shared and dedicated hosting setups. Similarly, Roundcube integrates with , with official updates and support for versions like 1.6 incorporated into its webmail ecosystem. ISPConfig, an open-source control panel, also supports Roundcube installation via dedicated tutorials and configurations, facilitating its use in Linux-based server management for email operations. Empirical underscores its prevalence: as of June 2025, security scans identified over 84,000 publicly exposed Roundcube installations vulnerable to a remote execution flaw (CVE-2025-49113), providing a conservative lower bound on global deployments amid widespread use in corporate networks, educational institutions, and web hosts. Usage analytics from W3Techs indicate Roundcube powers approximately 0.1% of all monitored websites, reflecting its niche but significant footprint in self-hosted interfaces. Independent assessments position it as the leading on-premises client, with claims of dominating the segment due to its compatibility and minimal resource demands on standard servers. Recent versions enhance enterprise suitability through features like authentication support, enabling secure integrations with identity providers, though high-volume scalability often requires custom caching and database optimizations given its /IMAP architecture. Adoption remains strong among small-to-medium providers, where plugin ecosystems and control panel embeddings track active installs indirectly via update metrics and community repositories.

Criticisms, Limitations, and Alternatives

Roundcube has faced criticism for its recurrent vulnerabilities, which some attribute to insufficient and resources for comprehensive audits and rapid patching in its community-driven development model, contrasting with proprietary solutions like Microsoft's Web App that benefit from dedicated enterprise teams. Users and security analysts have noted that these issues expose deployments to risks such as unauthorized if not promptly updated, with community forums highlighting delays in addressing exploits compared to more resourced alternatives. Performance limitations become evident with large mailboxes exceeding thousands of messages, where loading inboxes, searching, or sorting can take several seconds due to inefficient handling of IMAP fetches and lack of optimized indexing without additional plugins. This sluggishness is exacerbated in setups without server-side enhancements like Solr integration, making it less suitable for high-volume users without custom optimizations. Additionally, Roundcube lacks native end-to-end encryption, requiring third-party browser extensions like Mailvelope or PGP plugins for such functionality, which introduces dependency on external tools and potential compatibility issues. Alternatives include , a simpler, lightweight option favored for quick loading and basic interfaces but criticized as outdated with minimal modern features like drag-and-drop support. RainLoop offers a lighter footprint and faster performance for small-scale use but provides fewer extensibility options and has its own unresolved concerns, positioning it as less comprehensive than Roundcube. For more robust needs, proprietary systems like Outlook Web App deliver superior auditing and integration but at the cost of and licensing fees, while open-source options like Snappymail emphasize improved and usability over Roundcube's broader feature set.

References

  1. [1]
    Roundcube - Free and Open Source Webmail Software
    Roundcube webmail is a browser-based multilingual IMAP client with an application-like user interface. It provides full functionality you expect from an email ...DownloadAbout
  2. [2]
    The Roundcube Webmail suite - GitHub
    Roundcube Webmail is a browser-based multilingual IMAP client with an application-like user interface. It provides full functionality you expect from an email ...
  3. [3]
    Roundcube - Website hosting FAQ
    Creation: Roundcube was created by Thomas Bruederli in 2005 as a personal project. Bruederli aimed to develop a modern and intuitive webmail interface that ...
  4. [4]
    Software:Roundcube - HandWiki
    Feb 9, 2024 · After about two years of development the first stable release of Roundcube was announced in early 2008. In November 2023, the open-source file ...
  5. [5]
    About Roundcube Webmail
    Roundcube is a free, open-source webmail solution with a desktop-like interface, drag-and-drop, and features like spell check and security.
  6. [6]
    What Is Roundcube? - Themeisle
    Jul 30, 2025 · Key features of Roundcube · Multi-language support: Roundcube offers support for over 70 languages, making it accessible to a diverse audience.
  7. [7]
    Roundcube - The most popular on premise webmail - Nextcloud
    Roundcube for Enterprises is a lightweight, easy to manage and resource-efficient email platform that scales with your needs.
  8. [8]
    Roundcube's future at Nextcloud - An interview with the founders
    Nov 29, 2023 · Roundcube's initial release was in 2008 – 15 years ago! – yet this open source webmail software project is still deeply important in today's ...
  9. [9]
    Roundcube becomes part of Nextcloud - LWN.net
    Nov 29, 2023 · As a product, Roundcube has an established path to success on its own. With opportunities remaining to be explored, a direct merger between ...<|separator|>
  10. [10]
    Version History · roundcube/roundcubemail Wiki - GitHub
    Philip Weir edited this page last week · 8 revisions. Version 1.7. Initial release: TBC; PHP support: >=8.1 <=8.5. Version 1.6.
  11. [11]
    Thomas Brüderli – Professional Software Engineer at SBB CFF FFS
    Lead Developer. Roundcube Webmail Project. Juli 2005 – Nov. 2023 18 Jahre 5 Monate. Founder and project leader of the open source software project. Software ...
  12. [12]
    Roundcube Webmail 1.0.0 released
    Apr 7, 2014 · Roundcube Webmail 1.0.0 released. Published: 07 April 2014. Tags: releases · stable. We're very proud ...
  13. [13]
    Roundcube Webmail 1.0.0 released - Announce
    10:18 p.m.. Dear Roundcube users. We're very proud to announce the stable version 1.0 of Roundcube Webmail. After more than 8 years since the project was ...
  14. [14]
    Roundcube Webmail 1.3.0 released
    Jun 26, 2017 · We proudly announce the stable version 1.3.0 of Roundcube Webmail which is now available for download. With this milestone we introduce new ...
  15. [15]
    Roundcube Webmail 1.3.0 released - Announce
    We proudly announce the stable version 1.3.0 of Roundcube Webmail which is now available for download. With this milestone we introduce new features since the ...
  16. [16]
    Roundcube Webmail - endoflife.date
    Roundcube Webmail. php-runtime server-app. Last updated on 12 September 2025. Roundcube Webmail logo. Roundcube Webmail is a browser-based multilingual ...
  17. [17]
    Roundcube 1.4.0 released
    Nov 9, 2019 · Roundcube 1.4.0 released. Published: 09 November 2019. Tags: releases · stable. We proudly announce the final ...
  18. [18]
    Roundcube Webmail Screenshots
    Released with Roundcube version 1.4.0, Elastic is Roundcube's first official responsive skin. It has support for desktops, tablets and phones. desktop; tablet ...
  19. [19]
    Roundcube Project News - Latest Update Release Articles
    Roundcube Project News - Latest Update Release Articles. Update 1.5.11 released. 15 June 2025. This is the next service release to update the LTS version 1.5 ...
  20. [20]
    Releases · roundcube/roundcubemail - GitHub
    This is a security update to the stable version 1.6 of Roundcube Webmail. It provides fixes to recently reported security vulnerabilities.
  21. [21]
    Security updates 1.6.11 and 1.5.10 released - Roundcube Webmail
    We just published security updates to the 1.6 and 1.5 LTS versions of Roundcube Webmail. They both contain a fix for recently reported security vulnerability.
  22. [22]
    Roundcube Project News - Latest Release Articles
    Roundcube 1.7 beta was released on July 14, 2025. Update 1.5.11 was released on June 15, 2025, and security updates for 1.6.11 and 1.5.10 were released on June ...
  23. [23]
    Trac platform migrated to GitHub - Roundcube Webmail
    Mar 20, 2016 · Today we just migrated 4.8K tickets from the Trac database to GitHub issues, leaving the invalid and duplicate ones behind. Unfortunately the ...
  24. [24]
    Roundcube Open-Source Webmail Software Merges With Nextcloud
    Nov 29, 2023 · RoundCube-Next raised more than $100k in funding a number of years ago only to fail in delivering their revamped software.
  25. [25]
    Roundcube Next, what happened?
    Sep 24, 2015 · After a successful crowdfunding campaign raising over $100,000 dollars, they have apparently vanished. All activity on their twitter stream ...Missing: donations | Show results with:donations
  26. [26]
    Open source email pioneer Roundcube joins the Nextcloud family
    Nov 29, 2023 · Frank Karlitschek and Thomas Brüderli, founders of Nextcloud and Roundcube respectively, discuss the past, the present, and the future of this ...Missing: Bruederli | Show results with:Bruederli
  27. [27]
    Configuration · roundcube/roundcubemail Wiki - GitHub
    Roundcube webmail has over 200 configuration options that allow you to customize it according to your needs and taste and to perfectly interact with your email ...Missing: alpha | Show results with:alpha
  28. [28]
    Installation · roundcube/roundcubemail Wiki - GitHub
    This shell script is written for Debian with MySQL, SMTP and IMAP servers running on the localhost (SSL/TLS enabled and unauthenticated SMTP allowed from ...Missing: core technologies<|separator|>
  29. [29]
    Roundcube Licensing
    Roundcube is licensed under GNU GPL v3 or later, with exceptions for skins and plugins, which are not considered modifications of the software.
  30. [30]
    Roundcube License Change to GPLv3
    Feb 22, 2012 · Starting with the upcoming version 0.8, Roundcube will be licensed under the GNU General Public License (GPL) Version 3 or later (with ...
  31. [31]
    Roundcube Webmail 1.2.0 released
    May 22, 2016 · Drag-n-drop attachments from mail preview to compose window; Mail messages searching with predefined date interval; Improved security measures ...
  32. [32]
    Messages List — Roundcubemail documentation
    Threaded message listing​​ Instead of sorting messages by their date or subject, conversations spawning multiple messages can be grouped together as “Threads”. ...
  33. [33]
    Dev Accessibility Guidelines · roundcube/roundcubemail Wiki - GitHub
    Mar 21, 2016 · Keyboard Navigation. Every UI element SHALL be operable with the keyboard. That includes: Receiving focus using the tab key; Clearly ...
  34. [34]
    Sending Email Messages — Roundcubemail documentation
    The compose screen will contain the message text and all attachments already added. You can still add more attachments or remove some you don't want to forward.Missing: core features IMAP
  35. [35]
    Roundcube Webmail: The Complete Setup & User Guide - Hostman
    Here are some of the key features that make Roundcube stand out as an email client: User-Friendly Interface: Roundcube interface is easy to use, minimal, and ...
  36. [36]
    Roundcube Webmail: Comprehensive Features and Step ... - Contabo
    Oct 22, 2024 · In this guide, we'll walk you through Roundcube's features, explain the setup process, and help you decide if it's the right webmail solution for your needs.
  37. [37]
    Table Of Contents — Roundcubemail documentation
    Viewing Emails and Attachments · Sending Email Messages · Searching Email Messages · Organizing your Email Messages · Import/Export · Address Book · Directories ...Searching Contacts · Searching Email Messages · Login to the Webmail · Email<|separator|>
  38. [38]
    How to Use Roundcube Interface and Email Messaging Features
    Feb 21, 2025 · Roundcube allows users to manage email, use filters, create folders, write emails, and search emails. The interface has main windows for ...
  39. [39]
    Address Book — Roundcubemail documentation
    Address Book¶. The Address Book task provides access to contact data saved in your personal or shared address books and a rich interface to manage them.Missing: guide composing
  40. [40]
    Getting Started with Roundcube Webmail: A Beginner's Guide
    Feb 15, 2024 · You can also utilise features like composing emails, replying, forwarding and archiving messages efficiently. Sending and Receiving Emails.
  41. [41]
    Install Roundcube Webmail on Ubuntu 22.04/20.04 with PostgreSQL
    Nov 4, 2022 · MIME support; PGP ... You can create folders in Roundcube webmail and then create rules to filter email messages into different folders.<|separator|>
  42. [42]
    Plugin API · roundcube/roundcubemail Wiki - GitHub
    Plugins extend the functionality of Roundcube. They are not part of the core application but can be installed and activated individually.Missing: architecture | Show results with:architecture
  43. [43]
    Roundcube Plugins Repository
    The plugin repository for Roundcube is based on Composer to manage, install and update the plugins for your Roundcube installation.
  44. [44]
  45. [45]
    Skins
    ### Summary: Customizing Skins for Branding in Roundcube
  46. [46]
  47. [47]
    CVE-2014-9587 - CVE Record
    Multiple cross-site request forgery (CSRF) vulnerabilities in Roundcube Webmail before 1.0.4 allow remote attackers to hijack the authentication of ...
  48. [48]
  49. [49]
    Roundcube Webmail security vulnerabilities, CVEs, versions and ...
    This page lists vulnerability statistics for all versions of Roundcube Webmail. Vulnerability statistics provide a quick overview for security vulnerabilities ...Missing: history | Show results with:history
  50. [50]
    SMTP:VULN:ROUNDCUBE-UPLOAD-XSS - Juniper Networks
    Jul 29, 2025 · This signature detects attempts to exploit a known cross-site scripting vulnerability against Roundcube Webmail. It is due to insufficient ...Missing: sanitization | Show results with:sanitization
  51. [51]
    Roundcube Cross-Site Request Forgery (CSRF) Vulnerability (CVE ...
    An issue was discovered in Roundcube Webmail before 1.4.4. A CSRF attack can cause an authenticated user to be logged out because POST was not considered.
  52. [52]
    Roundcube Project News - Latest Security News
    We just published security updates to the 1.6 and 1.5 LTS versions of Roundcube Webmail. They both contain fixes for recently reported security vulnerabilities.Missing: volunteer auditing
  53. [53]
    CVE-2024-27354 Detail - NVD
    Mar 1, 2024 · An attacker can construct a malformed certificate containing an extremely large prime to cause a denial of service (CPU consumption for an isPrime primality ...
  54. [54]
    CVE-2025-49113 - CVE Record
    Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not ...
  55. [55]
    Over 1M Cock.li user records compromised via Roundcube exploits
    Jun 18, 2025 · BleepingComputer reports that all users of the German free privacy-focused email hosting server Cock.li since 2016 amounting to more than 1 ...
  56. [56]
    Cock.li breach exposes over 1 million email accounts - Paubox
    Jun 25, 2025 · A popular privacy-focused webmail service confirmed a data breach linked to outdated Roundcube software.
  57. [57]
    CISA Adds Two Known Exploited Vulnerabilities to Catalog
    Jun 9, 2025 · CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
  58. [58]
    U.S. CISA adds RoundCube Webmail and Erlang Erlang/OTP SSH ...
    CISA orders federal agencies to fix the vulnerabilities by June 30, 2025. Follow me on Twitter: @securityaffairs and Facebook and Mastodon.<|separator|>
  59. [59]
    Roundcube Webmail News
    We just published security updates to the 1.6 and 1.5 LTS versions of Roundcube Webmail. They both contain fixes for recently reported security vulnerabilities.Latest Release Articles · Security updates 1.6.11 and... · Update 1.6.10 released
  60. [60]
    Security updates 1.4.6 and 1.3.13 - Roundcube Community Forum
    Jun 7, 2020 · We recently published service and security updates to the stable version 1.4 and the LTS version 1.3 of Roundcube Webmail.Missing: post- | Show results with:post-
  61. [61]
    Is it possible to install Roundcube on shared server ? - Stack Overflow
    Oct 10, 2013 · cPanel ships with Roundcube already installed on the server by default with cPanel. You can access roundcube though the webmail interface using any of the ...
  62. [62]
    Input - Roundcube 1.6.0 official released - Plesk Forum
    Aug 3, 2022 · The released version 1.6 is not yet an LTS version, unlike version 1.5. Version 1.5 will be supported in Plesk 18.0.46 for all operating systems except CentOS7 ...Resolved - Roundcube - Oops... something went wrong - Plesk ForumIntegration of RoundCube WebMail - Plesk ForumMore results from talk.plesk.com
  63. [63]
    Tutorial: Using RoundCube Webmail With ISPConfig 3 On Debian ...
    This guide explains how to install the RoundCube webmail application on a Debian Wheezy server running ISPConfig and Apache2, and how to enable the ISPConfig 3 ...
  64. [64]
    Over 84000 Roundcube Webmail Installations Exposed to Remote ...
    Jun 10, 2025 · Security researchers have identified a critical vulnerability in Roundcube Webmail that affects over 84,000 unpatched installations worldwide, ...Missing: statistics | Show results with:statistics
  65. [65]
    Usage statistics and market share of Roundcube - W3Techs
    Roundcube is used by 0.1% of all the websites whose content management system we know. This is 0.1% of all websites.
  66. [66]
    Most popular webmail client Roundcube gets enterprise support
    Aug 8, 2024 · Nextcloud annoucnes official enterprise support for Roundcube, the world's most popular on-premises hosted webmail solution.
  67. [67]
    RoundCube - worth it? Safe? Something better? : r/selfhosted - Reddit
    Jul 4, 2024 · The webmail client is basic but does the job for a single account. I use snappymail (integrated with nextcloud) which is 100% better.Help Roundcube is driving me insane. : r/selfhostedThe sad state of self-hosted webmail : r/selfhostedMore results from www.reddit.comMissing: criticisms | Show results with:criticisms
  68. [68]
    Roundcube Webmail Flaws Allow Hackers to Steal Emails and ...
    Aug 7, 2024 · Researchers have disclosed details of security flaws in the Roundcube webmail software that could be exploited to execute malicious JavaScript in a victim's ...Missing: volunteer | Show results with:volunteer
  69. [69]
    Critical Roundcube Flaw Allows Attackers to Execute Remote Code
    Jun 2, 2025 · Given Roundcube's widespread deployment across corporate networks, educational institutions, and web hosting providers, the potential impact ...Missing: statistics | Show results with:statistics
  70. [70]
    Roundcube Performance - Everything very slow · Issue #5207 - GitHub
    Apr 16, 2016 · thanks @shadinamrouti currently roundcube have a bad preformance in large mailboxes ... 5 version.. see #7300 seems newer version of roundcube has ...
  71. [71]
    Slow displaying INBOX with thousands emails - Users
    Jul 19, 2024 · It takes about 5-7 seconds to display list of emails in folder. Pagination is set to 100 emails per page. I checked that IMAP server complete request "FETCH 1: ...very slow roundcube performance with 4000 message imap mailboxRe: Large mailboxes - Dev - Roundcube mailing listsMore results from lists.roundcube.net
  72. [72]
    How to improve Roundcube Webmail search performance in cPanel ...
    Jul 24, 2025 · Improve Roundcube search by installing the Solr plugin in cPanel, which enhances search speed, especially for large mailboxes.<|separator|>
  73. [73]
    Sending and reading encrypted messages via Roundcube Webmail
    You can enable end-to-end message encryption with minimal effort using the Roundcube webmail client and the Mailvelope browser extension/add-on.
  74. [74]
    Introducing enterprise support for Roundcube - Nextcloud
    Aug 8, 2024 · Offer customers easy End-to-End encrypted email OpenPGP-based based using Mailvelope. Mailvelope integrates closely with Roundcube, offering a ...
  75. [75]
    Squirrelmail vs Horde vs RoundCube - Web Hosting Forum
    Jan 8, 2017 · I like squirrelmail, easy loading and basic interface but seem Roundcube is better because it has drag-&-drop message management and full ...Missing: initial | Show results with:initial
  76. [76]
    Horde vs Roundcube vs SquirrelMail Webmail (2023)
    Jan 5, 2023 · We compare Roundcube, Horde, and SquirellMail and discuss which webmail application is better for you in 2023.Missing: initial motivations
  77. [77]
    What's the best self-hosted webmail client : r/selfhosted - Reddit
    Aug 3, 2022 · SquirrelMail and Roundcube feels like going back to the 2000s. I like rainloop but there are known security issues that haven't been fixed ...Best self hosted email/webmail: Rainloop or Roundcube?Choosing a self-hosted webmail : r/selfhostedMore results from www.reddit.com
  78. [78]
    The Best Self-Hosted Email Clients in 2024 | LinuxHostSupport
    Feb 29, 2024 · Roundcube is a modern webmail client that can be easily installed on any server. Its first stable version was released in 2014. Roundcube ...Roundcube · Rainloop · Zimbra