CVE-2026-74999

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the "Add to address book" action was subject to stored XSS.


We have discovered 9,367 live websites that are affected by CVE-2026-74999.

Run a Free Instant Scan




Affected Software

Product  RoundCube
Category Web Mail
Vulnerable Domains9,367 live websites (65% of RoundCube install base)
Vulnerable Versions
  • from 1.6 through 1.6.18
  • from 1.7 through 1.7.3
Vulnerable Versions Count21 versions ( 38% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Aug 17, 2026
  • Updated - Aug 17, 2026

Website Distribution by Country

Number of websites using CVE-2026-74999
United States1,329 websites



Germany1,477 websites
Spain524 websites
France469 websites
Brazil460 websites
Poland447 websites
Netherlands324 websites
Canada313 websites
Czech Republic268 websites
Russia243 websites

Website Distribution by TLD

Number of websites using CVE-2026-74999
.com2,158 websites
.net787 websites
.de681 websites
.com.br433 websites
.org417 websites
.pl357 websites
.nl257 websites
.cz240 websites
.it229 websites
.es209 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-74999

Top websites that are affected by CVE-2026-74999. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.**************.com United States**,***
****.********.net United States**,***
********.******.se Sweden**,***
****.*****.com Canada**,***
*******.**************.de Germany**,***
*******.*********.com United States**,***
*******.*****.**.uk GB**,***
****.**********.nl Netherlands**,***
*******.*****.hosting Ireland***,***
*******.*****.net Czech Republic***,***
See full domain list

FAQ

CVE-2026-74999 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in RoundCube
A total of 9,367 websites have been identified as vulnerable to CVE-2026-74999, based on global website indexing conducted by WebTechSurvey.
The RoundCube is affected by the CVE-2026-74999 vulnerability.
RoundCube versions up to 1.7.3 are vulnerable to CVE-2026-74999.
CVE-2026-74999 is resolved in version 1.7.3 of RoundCube.