CVE-2021-44026

Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.

  • Published Nov 19, 2021
  • CVSS 9.8 critical
  • 69.9% chance of exploitation in the next 30 days (EPSS)
  • In CISA's Known Exploited Vulnerabilities catalog
  • A fix is available

CVE-2021-44026 at the National Vulnerability Database