CVE-2026-54432

Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2 allows Stored Cross-Site Scripting (XSS). The issue occurs because the attachment MIME type is not properly escaped on the attachment-validation warning page.


We have discovered 9,391 live websites that are affected by CVE-2026-54432.

Run a Free Instant Scan




Affected Software

Product  RoundCube
Category Web Mail
Vulnerable Domains9,391 live websites (64% of RoundCube install base)
Vulnerable Versions
  • from 1.6 through 1.6.17
  • from 1.7 through 1.7.2
Vulnerable Versions Count19 versions ( 35% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Jul 14, 2026
  • Updated - Jul 15, 2026

Website Distribution by Country

Number of websites using CVE-2026-54432
United States1,283 websites



Germany1,463 websites
Spain527 websites
France505 websites
Brazil470 websites
Poland453 websites
Netherlands327 websites
Canada326 websites
Czech Republic274 websites
GB248 websites

Website Distribution by TLD

Number of websites using CVE-2026-54432
.com2,201 websites
.net768 websites
.de667 websites
.com.br446 websites
.org417 websites
.pl367 websites
.nl263 websites
.cz247 websites
.it237 websites
.es209 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-54432

Top websites that are affected by CVE-2026-54432. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.**************.com United States**,***
****.********.net United States**,***
********.******.se Sweden**,***
****.*****.com Canada**,***
*******.**************.de Germany**,***
*******.*********.com **,***
*******.*****.**.uk GB**,***
****.**********.nl Netherlands**,***
*******.*****.hosting Ireland***,***
*******.*****.net Czech Republic***,***
See full domain list

FAQ

CVE-2026-54432 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in RoundCube
A total of 9,391 websites have been identified as vulnerable to CVE-2026-54432, based on global website indexing conducted by WebTechSurvey.
The RoundCube is affected by the CVE-2026-54432 vulnerability.
RoundCube versions up to 1.7.2 are vulnerable to CVE-2026-54432.
CVE-2026-54432 is resolved in version 1.7.2 of RoundCube.