Decade-Old Critical Flaw in Roundcube Webmail Enables Authenticated Code Execution Attacks
A critical vulnerability (CVE-2025-49113, CVSS 9.9) in Roundcube webmail has been discovered after remaining hidden for ten years. This post-authenticated remote code execution flaw affects all versions prior to 1.6.11/1.5.10 LTS and allows authenticated users to execute arbitrary code thr...
