The Roundcube project reports:
- CSS declaration smuggling via un-encoded ampersand emission
- CSS property injection via body background attribute
- email header injection via bare CR in the subject field
- email header injection via C-escape \r in the recipient display name
- email header injection via identity’s organization field
- zero-click stored XSS via TNEF MIME tag injection in the attachment URL
- XSS in the HTML editor using text/enriched part content
- cross-user access in contact group membership (add/remove) in the SQL address book
- is_local_url() bypass via trailing-dot FQDN in stylesheet URL
- remote content blocking bypass via CSS escapes in FuncIRI attributes
- remote-content blocker bypass via SVG SMIL src animation
- SSRF bypass in Roundcube CSS proxy via hexadecimal IPv6-mapped IPv4 addresses