Roundcube
The Roundcube Webmail suite
Alternative to: gmail, outlook, yahoo mail
1.7.3
2026-08-09This security update for Roundcube Webmail 1.7 fixes multiple critical vulnerabilities including RCE, SSRF, XSS, and command injection, alongside various general bug fixes.
1.6.18
2026-08-09Security update for Roundcube Webmail 1.6 addressing multiple vulnerabilities including RCE, SSRF, XSS, and command injection.
1.7.2
2026-07-05This security update for Roundcube Webmail 1.7 fixes multiple vulnerabilities including XSS, SSRF, and DoS, alongside various bug fixes for static file handling and OIDC support.
1.6.17
2026-07-05Security update for Roundcube 1.6 fixing multiple vulnerabilities including XSS, SSRF, DoS, and TNEF decoder issues, while adding Enigma plugin enhancements.
1.7.1
2026-05-24This security update for Roundcube 1.7 addresses multiple vulnerabilities including XSS, SQL injection, SSRF, and code injection, while adding HKP v1 protocol support and various bug fixes.
1.6.16
2026-05-24Security update for Roundcube 1.6 LTS addressing multiple vulnerabilities including XSS, SQL injection, SSRF, and remote code execution.
1.7.0
2026-05-10Roundcube 1.7 introduces Markdown support, improved OAuth2/OIDC, advanced search syntax, and a mandatory public_html entry-point while updating PHP requirements.
1.7-rc6
2026-03-29Roundcube 1.7 release candidate fixes a security vulnerability regarding SVG remote image loading and adds new configuration and driver support.
1.6.15
2026-03-29This security update for Roundcube 1.6 fixes a remote image loading vulnerability and resolves regressions related to mail search and data URL images.
1.5.15
2026-03-29This security update for Roundcube 1.5 fixes a remote image loading vulnerability via SVG Animate and resolves regressions related to mail search and data URL images.
1.7-rc5
2026-03-18Roundcube Webmail 1.7 release candidate focuses on fixing multiple security vulnerabilities, including XSS, SSRF, and arbitrary file write, alongside general bug fixes and a new password hashing method.
1.6.14
2026-03-18Security update for Roundcube 1.6 addressing multiple vulnerabilities including arbitrary file write, XSS, SSRF, and password change bugs, alongside a Postgres IPv6 connection fix.
1.5.14
2026-03-18This security update for Roundcube 1.5 fixes multiple vulnerabilities, including arbitrary file write, password change bugs, IMAP injection, and XSS issues.
1.7-rc4
2026-02-13Roundcube 1.7-rc4 fixes file permission issues during release builds and repairs a broken configuration download link in the installer.
1.7-rc3
2026-02-10Roundcube 1.7-rc3 fixes two security vulnerabilities, resolves various bugs, and introduces several configuration and feature enhancements.
1.6.13
2026-02-08Security update for Roundcube 1.6 fixing CSS injection, an SVG-based remote image blocking bypass, and a Managesieve date test issue.
1.5.13
2026-02-08Security update for Roundcube 1.5 LTS fixing CSS injection and remote image blocking bypass vulnerabilities.
1.7-rc2
2025-12-15This release candidate for version 1.7 addresses two security vulnerabilities and corrects a Postgres database migration syntax error.
1.6.12
2025-12-14Security update for Roundcube 1.6 addressing XSS and information disclosure vulnerabilities, alongside various bug fixes and PHP 8.5 compatibility improvements.
1.5.12
2025-12-14Security update for Roundcube 1.5 LTS fixing Cross-Site-Scripting and Information Disclosure vulnerabilities.
1.7-rc
2025-12-12Roundcube 1.7 RC introduces a Markdown editor plugin, improved contact search and CSV import, and several security updates.
1.7-beta2
2025-10-01Roundcube 1.7 beta release adds PHP 8.5 support, IPv6 database DSN support, various security sanitization improvements, and drops support for Internet Explorer.
1.7-beta
2025-07-14Beta release for version 1.7 introducing PHP 8.4 support, advanced mail search, and OAuth2 improvements, while requiring PHP 8.1+ and introducing several breaking changes.
1.5.11
2025-06-15This release fixes a PHP 5.5 compatibility issue introduced in version 1.5.10.
1.6.11
2025-06-01This security update for Roundcube 1.6 fixes a post-auth RCE vulnerability via PHP object deserialization and includes various bug fixes for OAuth, LDAP, and the UI.
1.5.10
2025-06-01Security update for Roundcube 1.5 fixing a post-auth RCE vulnerability and bugs related to managesieve_kolab_master and SVG images.
1.6.10
2025-02-08Stable update featuring IMAP extension support, OIDC token authentication improvements, and various bug fixes for PHP warnings, vCard handling, and database configurations.
1.6.9
2024-09-01This stable service release for version 1.6 fixes two regressions related to image attachment handling and HTML message styling.
1.5.9
2024-09-01This service release for version 1.5 fixes two regressions related to image attachment processing and HTML message styling.
1.6.8
2024-08-04This security update for Roundcube 1.6 fixes multiple XSS vulnerabilities, an information leak, and various bugs related to Sieve scripts and email attachments.
1.5.8
2024-08-04Security update for Roundcube 1.5 fixing XSS vulnerabilities and an information leak via CSS filtering.
1.6.7
2024-05-19This security update for Roundcube 1.6 fixes multiple XSS vulnerabilities, a command injection flaw on Windows, and various general bugs.
1.5.7
2024-05-19Security update for Roundcube 1.5 fixing XSS vulnerabilities, a Windows command injection flaw, and various bugs in Enigma and TinyMCE.
1.6.6
2024-01-20This service release for version 1.6 includes various bug fixes, PHP8 compatibility updates, and a security update for TinyMCE.
1.6.5
2023-11-05This security update for Roundcube 1.6 fixes a cross-site scripting (XSS) vulnerability related to attachment previews and downloads, along with several PHP errors and UI bugs.
1.5.6
2023-11-05This security update fixes a cross-site scripting (XSS) vulnerability related to attachment preview and download Content-Type/Content-Disposition settings.
1.6.4
2023-10-16Security update addressing a cross-site scripting (XSS) vulnerability in SVG handling, along with various PHP8, Windows, and Managesieve fixes.
1.5.5
2023-10-16Security update for Roundcube 1.5 that fixes a cross-site scripting (XSS) vulnerability related to SVG handling in HTML messages.
1.4.15
2023-10-16This security update for Roundcube Webmail 1.4 fixes a cross-site scripting (XSS) vulnerability in SVG handling and improves PHP 5.4 compatibility.
1.5.4
2023-09-18This security update fixes an XSS vulnerability in plain text linkrefs and addresses several bugs related to logging, vCard exports, date formatting, and JavaScript encoding.
1.4.14
2023-09-18This security update fixes a cross-site scripting (XSS) vulnerability in plain text message linkref handling and an Enigma private key synchronization issue.
1.6.3
2023-09-15This security update fixes a cross-site scripting (XSS) vulnerability and resolves multiple bugs, including regressions and PHP warnings.
1.6.2
2023-07-02This stable service release for version 1.6 includes numerous bug fixes, stability improvements, and the addition of Uyghur localization.
1.6.1
2023-01-23This service release for version 1.6 includes various bug fixes and improvements for PHP 8.1/8.2 compatibility, session handling, and general system stability.
1.6.0
2022-07-28Roundcube 1.6 introduces PHP 8.1 support, HTML response snippets, mail purging options, and updated service connection configurations, while dropping support for PHP versions below 7.3.
1.5.3
2022-06-26This release provides various bug fixes and improvements, specifically targeting PHP8 compatibility and Enigma PGP functionality.
1.6-rc
2022-06-12Roundcube 1.6 release candidate includes jQuery-UI updates, ssha256 password support, and various bug fixes for attachments, encoding, and the HTML editor.
1.6-beta
2022-03-06Roundcube 1.6 beta adds PHP 8.1 support, simplifies service connection configurations, and introduces HTML snippet support and improved mail purging options.
1.5.2
2021-12-30This service release provides various fixes for OAuth and other features, including a security fix for a cross-site scripting (XSS) vulnerability.
1.4.13
2021-12-30This security update fixes a cross-site scripting (XSS) vulnerability triggered by malicious CSS content in HTML messages.
1.5.1
2021-11-28This service release provides various small fixes and improvements following the 1.5.0 stable release.
1.4.12
2021-11-12This security update for Roundcube Webmail 1.4 fixes SQL injection and XSS vulnerabilities along with various bug fixes and general improvements.
1.3.17
2021-11-12Security update for LTS version 1.3 fixing XSS and SQL injection vulnerabilities.
1.5.0
2021-10-18Roundcube 1.5.0 introduces PHP 8.0 support, dark mode for Elastic skin, OAuth2 support, and full unicode support for MySQL databases.
1.5-rc
2021-07-03Roundcube 1.5 release candidate introduces XOAUTH2 support for Managesieve, IMAP LITERAL- extension, RFC 2231 encoded names, and various bug fixes and security improvements.
1.5-beta
2021-02-25Beta release of version 1.5 introducing PHP 8.0 support, OAuth2/XOauth, dark mode for Elastic skin, and full unicode support for MySQL.
1.4.11
2021-02-08This update addresses a stored XSS vulnerability in HTML messages and includes general stability and compatibility improvements.
1.4.10
2020-12-27This security update for Roundcube Webmail 1.4 fixes a stored XSS vulnerability (CVE-2020-35730) and includes several general bug fixes.
1.3.16
2020-12-27This security update for LTS version 1.3 fixes a stored cross-site scripting (XSS) vulnerability (CVE-2020-35730).
1.2.13
2020-12-27Security update for LTS version 1.2 fixing a stored cross-site scripting (XSS) vulnerability (CVE-2020-35730).
1.4.9
2020-09-27Roundcube Webmail 1.4 stable update featuring bug fixes for email composition, UI improvements for the Elastic skin, and an update to TinyMCE 4.9.11.
1.4.8
2020-08-10This service and security update for Roundcube 1.4 addresses several XSS vulnerabilities and includes various general bug fixes and improvements.
1.3.15
2020-08-10Security update for LTS version 1.3 fixing two cross-site scripting (XSS) vulnerabilities involving malicious SVG and MathML content in HTML messages.
1.2.12
2020-08-10Security update for LTS version 1.2 fixing two cross-site scripting (XSS) vulnerabilities involving malicious SVG and Math HTML content.
1.4.7
2020-07-05This service and security update fixes a cross-site scripting (XSS) vulnerability and includes various general bug fixes and improvements.
1.3.14
2020-07-05This security update for LTS version 1.3 fixes a cross-site scripting (XSS) vulnerability related to HTML messages with malicious svg/namespace (CVE-2020-15562).
1.2.11
2020-07-05This security update for LTS version 1.2 fixes a cross-site scripting (XSS) vulnerability involving malicious svg/namespaces (CVE-2020-15562).
1.4.6
2020-06-07Fixes a regression in the installer's SMTP test section.
1.3.13
2020-06-07This release fixes a regression in the installer's SMTP test section affecting new installations.
1.4.5
2020-06-02Service and security update for Roundcube 1.4 addressing multiple XSS vulnerabilities and providing general bug fixes and improvements.
1.3.12
2020-06-02Service and security update for Roundcube Webmail LTS 1.3 addressing four XSS vulnerabilities and including general improvements.
1.4.4
2020-04-29This security and service update addresses four security vulnerabilities, including XSS and remote code execution, alongside various general bug fixes and improvements.
1.3.11
2020-04-29Service and security update for Roundcube 1.3 LTS addressing four security vulnerabilities including XSS, CSRF, RCE, and path traversal, along with general bug fixes.
1.2.10
2020-04-29Security update for LTS version 1.2 fixing XSS, CSRF, remote code execution, and path traversal vulnerabilities.
1.4.3
2020-02-19Roundcube Webmail 1.4 stable update featuring general fixes and improvements for the Elastic theme and core plugins like Enigma, Managesieve, and Markasjunk.
1.4.2
2020-01-01This stable service release for Roundcube 1.4 includes various bug fixes and improvements across the Plugin API, Managesieve, installer, and UI components.
1.4.1
2019-11-22This service release for version 1.4 clarifies breaking changes regarding SMTP defaults and password charset while fixing several bugs and adjusting the 401 unauthorized status behavior.
1.4.0
2019-11-09Roundcube 1.4 introduces the responsive Elastic skin, mobile support, Redis and Memcached cache, and enhanced email features alongside numerous bug fixes and library updates.
1.4-rc2
2019-09-16This second release candidate for version 1.4 introduces the Elastic skin, jQuery 3.4.1, and numerous bug fixes and security improvements.
1.3.10
2019-08-28This service release for Roundcube Webmail 1.3 includes various bug fixes and security updates regarding CSS, HTML cleanup, and Enigma encryption.
1.3.9
2019-03-31This service release for Roundcube Webmail 1.3 includes various bug fixes backported from the master branch to improve stability and compatibility.
1.4-rc1
2019-02-28This release candidate for version 1.4 introduces the responsive Elastic skin, numerous password driver enhancements, and various bug fixes and plugin API updates.
1.3.8
2018-10-26Roundcube 1.3 service release providing a security fix for XSS and compatibility updates for PHP 7.3, MySQL 8, Courier-IMAP, and Dovecot.
1.4-beta
2018-08-25Roundcube 1.4 beta introduces a new responsive Elastic skin, Redis cache support, SMTPUTF8, and various enhancements to Mailvelope and Managesieve integrations.
1.3.7
2018-07-27Service release updating Roundcube 1.3 with various bug fixes and a security mitigation for the EFAIL issue in OpenPGP.
1.2.9
2018-04-29Fixes a regression in IMAP command injection protection that disabled actions operating on all selected messages.
1.1.12
2018-04-29Fixes a regression in IMAP command injection protection that prevented actions from operating on all selected messages.
1.1.11
2018-04-18Security update fixing an IMAP command injection vulnerability (CVE-2018-9846) and an issue with remote content blocking in HTML messages.
1.2.8
2018-04-17Security update fixing an IMAP command injection vulnerability (CVE-2018-9846) and improving remote content blocking for HTML messages.
1.3.6
2018-04-11Security update fixing an IMAP command injection vulnerability (CVE-2018-9846) and providing PHP 7.2 compatibility and Enigma plugin improvements.
1.3.5
2018-03-15Service release for Roundcube 1.3 featuring various bug fixes, improved HTML editor font sizes, and a security fix for remote content blocking.
1.3.4
2018-01-14Service release for Roundcube 1.3 providing PHP 7.2 compatibility and various bug fixes across contacts, IMAP handling, and security.
1.3.3
2017-11-08Security update fixing a file disclosure vulnerability and improving mailto link decoding and non-ASCII character handling.
1.2.7
2017-11-08Security update for version 1.2 fixing a file disclosure vulnerability and several bugs related to message rendering and Managesieve parsing.
1.1.10
2017-11-08Security update for version 1.1 fixing a file disclosure vulnerability caused by insufficient input validation in file-based attachment plugins.
1.0.12
2017-11-08Security update for LTS version 1.0 that fixes a potential file disclosure vulnerability in file-based attachment plugins.
1.3.2
2017-10-31This service release for version 1.3 includes various bug fixes, translation updates, and a wording change for the 'mark as read' setting.
1.2.6
2017-09-10This service and security update for version 1.2 includes various bug fixes, UI improvements, and a fix for a potential XSS vulnerability.
1.3.1
2017-09-04This service release for version 1.3 includes bug fixes, a security patch for an XSS vulnerability, PHP optimizations, and UI improvements to the mailbox view and message list behavior.
1.3.0
2017-06-26Roundcube 1.3 introduces a three-column widescreen layout, WEBP and MathML support, and various plugin improvements, while dropping support for legacy browsers and PHP 5.3.