← Back to browse · API

CVE-2025-49113

Severity
CRITICAL
CVSS
9.9
EPSS
0.97694
Risk score
59.19
CISA KEV
Yes
PoC
No
Published
2025-06-02
Modified
2026-02-21
First seen
2026-08-07
Aliases
EUVD-2025-16605, GHSA-8J8W-WWQC-X596
Products
Roundcube:Webmail, bulwarkmail:Webmail 0 <1.5.10, bulwarkmail:Webmail 1.6.0 <1.6.11
Sources
cisa.gov CVE-2025-49113
euvd EUVD-2025-16605

Description

Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP Object Deserialization.

References