cancel
Showing results for 
Search instead for 
Did you mean: 

Greenby Roundcube version

ElectricString
Hooked
Posts: 9
Registered: ‎29-08-2007

Greenby Roundcube version

Greenby Roundcube is v1.5.2 NOT latest v1.7.4 !

Roundcube version v1.5.2 was released on December 30, 2021.

Can anybody give a satisfactory explanation for this?

11 REPLIES 11
jab1
The Full Monty
Posts: 25,097
Thanks: 9,052
Fixes: 385
Registered: ‎24-02-2012

Re: Greenby Roundcube version

Ask Greenby?

John
Townman
Superuser
Superuser
Posts: 29,211
Thanks: 13,370
Fixes: 249
Registered: ‎22-08-2007

Re: Greenby Roundcube version

And what material differences are there between these versions which you consider to be critical?

Superusers are not staff, but they do have a direct line of communication into the business in order to raise issues, concerns and feedback from the community.

stuck
Seasoned Pro
Posts: 430
Thanks: 213
Fixes: 4
Registered: ‎21-05-2009

Re: Greenby Roundcube version


@Townman wrote:

...material differences...


Surely you would hope that the current version would include security fixes, which would make updating critical would it not?

Townman
Superuser
Superuser
Posts: 29,211
Thanks: 13,370
Fixes: 249
Registered: ‎22-08-2007

Re: Greenby Roundcube version

If there are indeed security fixes, then one would agree.  If there are none (no one has indicated the presence of such) then there is only merit in updating it, if the changed functionality is deemed worth the effort of upgrading.

Remember that invariably upgrades brings a raft of new bugs breaking things which used to work.  If it ain't broke ...

Superusers are not staff, but they do have a direct line of communication into the business in order to raise issues, concerns and feedback from the community.

Champnet
Hero
Posts: 3,310
Thanks: 1,298
Fixes: 21
Registered: ‎25-07-2007

Re: Greenby Roundcube version


@Townman wrote:

Remember that invariably upgrades being a raft of new bugs breaking things which used to work.  If it ain't broke ...


For that reason, in my early life dealing with Dec Vax updates, even number versions were avoided.........

stuck
Seasoned Pro
Posts: 430
Thanks: 213
Fixes: 4
Registered: ‎21-05-2009

Re: Greenby Roundcube version


@Townman wrote:

...security fixes, then one would agree...


According to this:

https://roundcube.net/news/updates/

v1.7 does include security updates.

Also, v1.5 reached end of life back in May so it will not receive any more security updates.

ElectricString
Hooked
Posts: 9
Registered: ‎29-08-2007

Re: Greenby Roundcube version


@jab1 wrote:

Ask Greenby?


I have, but I don’t expect an answer anytime soon.

 

I also googled it.
Question: Is there any reason to keep using v1.5.2 of Roundcube?

The answer was less than reassuring.

Answer (AI Overview):

No, there is absolutely no valid reason to continue using Roundcube v1.5.2. In fact, running this version is a massive security liability.

Roundcube v1.5.2 was released in December 2021 and is severely outdated. The entire 1.5.x Long Term Support (LTS) cycle officially reached its End of Life (EOL) on May 10, 2026, meaning it no longer receives even critical security updates from the Roundcube Project.

The Risks of Staying on v1.5.2

Critical Vulnerabilities & Active Exploits: Since 2021, dozens of critical vulnerabilities have been discovered that directly affect v1.5.2. These include zero-click Cross-Site Scripting (XSS) flaws, authenticated Remote Code Execution (RCE via CVE-2025-49113), and pre-authentication SQL injections. Many of these flaws are actively tracked by CISA and are being actively exploited in the wild by threat actors to steal emails and take over servers.

No PHP 8.1+ Support: Roundcube 1.5 only supports up to PHP 8.0. PHP 8.0 itself is completely end-of-life, meaning your underlying server environment is likely insecure as well.

Missing Features: You are missing out on major stability fixes, markdown mail rendering/composing, better OAuth2/OIDC integration, and the security enhancements of modern deployment methods.

What You Should Do Instead


You should upgrade immediately to a supported version. The currently maintained versions are v1.6.x and the latest stable v1.7.x (such as v1.7.4 released in September 2026)
If your server is locked onto an older PHP version (PHP 7.3 to 8.3), upgrade to the latest v1.6.x release.
If your server supports PHP 8.1 or newer, upgrade directly to the latest stable v1.7.x release.

 

Dan_the_Van
Superuser
Superuser
Posts: 4,977
Thanks: 3,283
Fixes: 148
Registered: ‎25-06-2007

Re: Greenby Roundcube version

@ElectricString 

If you have concerns using roundcube I would suggest using a email client app instead, I would recommend thunderbird.

Superusers are not staff, but they do have a direct line of communication into the business in order to raise issues, concerns and feedback from the community.

MoonMan
Dabbler
Posts: 11
Thanks: 6
Registered: ‎19-11-2025

Re: Greenby Roundcube version


@Champnet wrote:


... Dec Vax updates.........


Eeee, those were the days 😀

ExForce9
Seasoned Pro
Posts: 527
Thanks: 250
Fixes: 6
Registered: ‎04-07-2026

Re: Greenby Roundcube version

From Roundcube 1.5.2 (late 2021) to 1.7.4 (September 2026), the main improvements came in two major version jumps (1.5 → 1.6 and 1.6 → 1.7), plus many security fixes, bugfixes, and refinements in the point releases.

Major changes in 1.6 (released July 2022)

  • Full PHP 8.1 support (dropped PHP < 7.3).
  • HTML-format responses/snippets.
  • Option to purge deleted mails older than 30/60/90 days.
  • Unified/simplified connection config options (e.g. default_host → imap_host, smtp_server → smtp_host; ports/TLS handled via host strings).
  • Classic and Larry skins removed from the main packages (installable separately via Composer).
  • SQLite now uses foreign keys (requires SQLite ≥ 3.6.19).
  • Various codebase cleanups and smaller improvements.

Major changes in 1.7 (released May 2026)

After nearly four years of development, this was the bigger leap:

New features / UX

  • Markdown mail rendering and composing (new markdown_editor plugin).
  • Quick-actions mouse-over menu on the messages list.
  • Advanced mail search syntax (more powerful, though without a full UI).
  • Improved OAuth2/OIDC support (OIDC discovery, OIDC logout, better token handling, etc.).
  • Better contact search (scope parameter, choose any fields on CSV import).
  • Tooltip with folder name in multi-folder widescreen lists.
  • System health-check CLI script.
  • Various smaller UI and search enhancements (e.g. $HasAttachment/$HasNoAttachment keywords).

Security & architecture

  • Mandatory public_html/ entry-point (all static resources served via static.php) — significantly better protection for installations.
  • Dropped support for Internet Explorer.
  • Dropped MS SQL Server and Oracle database support.
  • APC cache driver removed (replaced by APCu).
  • Many hardening changes (stricter sanitization, better remote-content blocking, etc.).

Other technical changes

  • Minimum PHP version raised to 8.1 (supports up to ~8.5).
  • smtp_log default changed to false.
  • contact_search_name removed in favor of contactlist_name_template.
  • Session property changed replaced by expires_at.
  • Insecure Virtualmin password driver removed.
  • Uploads metadata moved to a separate SQL table (instead of the session).
  • Updated dependencies (jQuery, OpenPGP.js, etc.), stricter code-quality checks, and general codebase cleanup.

1.7.x point releases (1.7.1 → 1.7.4)

These were primarily security-focused (dozens of fixes for XSS, SSRF, header injection, remote-content bypasses via SVG/CSS, TNEF/DoS issues, password-plugin problems, IMAP injection, etc.). They also included smaller functional improvements such as:

  • Enigma: automatic public-key lookup via HKP.
  • Better OAuth/OIDC edge-case handling.
  • Fixes for static resource serving, vCard import, TNEF decoding, Redis/Memcache sessions, etc.

Summary of the overall upgrade path

Area 1.5.2 → 1.6 1.6 → 1.7
PHP 7.3–8.1 8.1–8.5
Key new features HTML snippets, purge options Markdown, quick actions, advanced search, better OAuth
Security posture Incremental Major (public_html, many sanitizer fixes)
Skins / DB Classic/Larry optional IE + MS SQL/Oracle dropped
Config Host/port unification Several options removed/renamed
 
 

Note: 1.5.x is fully EOL. 1.6.x is now LTS (security fixes only). 1.7.x is the current stable branch.

 

ExForce9
Seasoned Pro
Posts: 527
Thanks: 250
Fixes: 6
Registered: ‎04-07-2026

Re: Greenby Roundcube version

Changelog Roundcube Webmail

This file includes only changes we consider noteworthy for users, admins and plugin authors. For a full view please look at the git history.

Release 1.7.4

  • Use X-Content-Type-Options:nosniff for attachment previews and downloads (#10308)
  • zipdownload: Fix attachment filename sanitisation of backslash and control characters (#10325)
  • Security: Fix CSS declaration smuggling via un-encoded ampersand emission
  • Security: Fix CSS property injection via body background attribute
  • Security: Fix email header injection via bare CR in the subject field
  • Security: Fix email header injection via C-escape \r in the recipient display name
  • Security: Fix email header injection via identity's organization field
  • Security: Fix zero-click stored XSS via TNEF MIME tag injection in the attachment URL
  • Security: Fix XSS in the HTML editor using text/enriched part content
  • Security: Fix cross-user access in contact group membership (add/remove) in the SQL address book
  • Security: Fix is_local_url() bypass via trailing-dot FQDN in stylesheet URL
  • Security: Fix remote content blocking bypass via CSS escapes in FuncIRI attributes
  • Security: Fix remote-content blocker bypass via SVG SMIL src animation
  • Security: Fix SSRF bypass in Roundcube CSS proxy via hexadecimal IPv6-mapped IPv4 addresses

Release 1.7.3

  • OAuth: Don't log an error when a refreshed token's TTL is below refresh_interval (#10213)
  • Fix out-of-bounds string reads on truncated compressed-RTF in the TNEF decoder (#10269)
  • Fix bug where searching in example_addressbook plugin was reporting zero results despite matches (#9022)
  • Fix vCard import mis-detecting folded continuation lines as BEGIN/END:VCARD (#9593)
  • Fix bug where the php session driver practically disabled session.lazy_write optimization (#9885, #10248)
  • Fix bug where dates could get displayed shifted back one day in some places (#9403)
  • Fix regression where it wasn't possible to hide a skin logo image anymore (#10254)
  • Fix decoding of multi-segment RFC2231 extended attachment filenames (#10268)
  • Fix vCard import silently dropping properties with a non-item group prefix (#10271)
  • Fix so REQUEST_URI is used as a fallback if PATH_INFO is empty in static.php (#10181)
  • Security: Add basic validation for content proxied by the css proxy [CVE-2026-74998]
  • Security: Fix SSRF bypass via specific local address URLs using 100.64.0.0/10 and fe80::/10 nets [CVE-2026-75006]
  • Security: Fix SSRF filter bypass via various forms of nip.io/sslip.io hostnames evading is_local_url() check [CVE-2026-75006]
  • Security: Fix remote content blocking bypass via unclosed url() in a FuncIRI attribute [CVE-2026-75003]
  • Security: Fix LDAP filter injection via unescaped %u/%fu/%d substitution into the search_filter [CVE-2026-75007]
  • Security: Fix arbitrary Sieve script injection via a filter rule name bypassing managesieve_disabled_actions [CVE-2026-75004]
  • Security: Fix RCE via cmd_learn driver of markasjunk plugin [CVE-2026-74997]
  • Security: Fix IMAP command injection via mail search and LITERAL+ byte-count desynchronization [CVE-2026-75002]
  • Security: Fix password's modoboa driver leak of an authentication token to a user-controlled host [CVE-2026-75010]
  • Security: Fix stored XSS in "Add to address book" action [CVE-2026-74999]
  • Security: Fix HTML/CSS sanitization bypass via SVG animate by attribute [CVE-2026-75000]

Release 1.7.2

  • Add HEAD request handler to the static.php
  • Fix so the oauth_password_claim claim is retrieved via token or userinfo request (#9631)
  • Fix bug where static.php would return a 416 error on a specific Range request (#10194)
  • Fix bug where configured skin logo wasn't loaded via static.php resulting in 404 error (#10191)
  • Fix bug where installto.sh would fail if public_html folder does not exist in the target directory (#10202)
  • Revert "Prefer 8bit over quoted-printable for HTML parts, when force_7bit is disabled (#8477)" (#10198)
  • Fix incorrect unfolding of folded lines when importing vCard 2.1 contacts (#9647)
  • Fix bug where Imagick could leave large temporary files on failure (#10230)
  • Fix bug where redis/memcache session could have been updated more often than needed
  • Fix support for untyped tokens in OIDC backchannel logout, require unset nonce (#10097)
  • Security: Fix an infinite loop in TNEF (winmail.dat) decoder (#10193) [CVE-2026-62642]
  • Security: Fix various vulnerabilities in the password plugin using session-injected username [CVE-2026-62644]
  • Security: Fix stored XSS via unescaped attachment MIME type on the attachment-validation warning page [CVE-2026-54432]
  • Security: Fix SSRF bypass via specific local address URLs - two new cases [CVE-2026-62643]
  • Security: Fix zero-click stored XSS in plain-text rendering [CVE-2026-54433]
  • Security: Fix DoS via crafted compressed-RTF size in the TNEF (winmail.dat) file [CVE-2026-62641]

Release 1.7.1

  • Enigma: Support automatic public key lookup (import) using HKP v1 protocol (#5314)
  • Managesieve: Fix error when a mail message contains duplicate List-Id header (#10186)
  • Clarified Elastic installation instructions (#10163)
  • Fix so "has:attachment" search uses $HasAttachment/$HasNoAttachment keywords (#10168)
  • Fix potential too long value in IMAP ID command (#10136)
  • Fix redis/memcache disconnection in rcube::sleep() (#10127)
  • Fix so static resources, e.g. skin_logo can be put inside the public_html directory (#10160)
  • Fix so REQUEST_URI is used as a fallback if PATH_INFO is not set in static.php (#10181)
  • Fix assets_path feature and remove dependency on PATH_INFO (#10185)
  • Fix MySQL upgrade on MySQL < 8.0 and MariaDB < 10.5.3 (#10188)
  • Security: Fix stored XSS/HTML/CSS injection in subject field of the draft restore dialog [CVE-2026-48849]
  • Security: Fix CSS injection bypass in HTML sanitizer via SVG <animate attributeName="style"> [CVE-2026-48848]
  • Security: Fix pre-auth SQL injection in virtuser_query plugin via preg_replace backslash escape bypass [CVE-2026-48842]
  • Security: Fix SSRF bypass via specific local address URLs [CVE-2026-48843]
  • Security: Fix bypass of remote image blocking via CSS var() [CVE-2026-48846]
  • Security: Fix local/private URL fetch bypass when remote resources were not allowed [CVE-2026-48845]
  • Security: Fix pre-auth arbitrary file delete via redis/memcache session poisoning bypass [CVE-2026-48847]
  • Security: Fix code injection vulnerability - remove support for code evaluation in LDAP autovalues option [CVE-2026-48844]

Release 1.7.0

  • Bump OpenPGPjs version to 6.3.0
  • Allow cidr (subnets) in proxy_whitelist (#7103)
  • Zipdownload: Fix message date time zone in mbox export (#10147)

Release 1.7-rc6

  • Added support for arrays in smtp_user and smtp_pass config options (#10083)
  • Added system health checker CLI script (#10106)
  • Stricter recognition of an Ajax request (#10118)
  • Password: Added Stalwart driver (#10114)
  • Fix regression where some data url images could get ignored/lost (#10128)
  • Security: Fix SVG Animate FUNCIRI Attribute Bypass — Remote Image Loading via fill/filter/stroke [CVE-2026-35545]

Release 1.7-rc5

  • Password: Add nt-binary hashing method (#10096)
  • Fix URL matching for domain names with port numbers (#10105)
  • Fix PHP fatal error when using IMAP cache (#10102)
  • Fix Postgres connection using IPv6 address (#10104)
  • Fix bug where rel=stylesheet part of a <link> could get removed
  • Security: Fix pre-auth arbitrary file write via unsafe deserialization in redis/memcache session handler [CVE-2026-35537]
  • Security: Fix bug where a password could get changed without providing the old password [CVE-2026-35541]
  • Security: Fix IMAP Injection + CSRF bypass in mail search [CVE-2026-35538]
  • Security: Fix remote image blocking bypass via various SVG animate attributes [CVE-2026-35543]
  • Security: Fix remote image blocking bypass via a crafted body background attribute [CVE-2026-35542]
  • Security: Fix fixed position mitigation bypass via use of !important [CVE-2026-35544]
  • Security: Fix XSS issue in a HTML attachment preview [CVE-2026-35539]
  • Security: Fix SSRF + Information Disclosure via stylesheet links to a local network hosts [CVE-2026-35540]

Release 1.7-rc4

  • Ensure correct file permissions when building a release.
  • Installer: Fix broken link to download the created configuration file (#10092)

Release 1.7-rc3

  • Support request_url config option for resolving relative URLs (#9868)
  • Support X-Forwarded-Host/X-Forwarded-Port in self URLs generation (#9952)
  • Support $HasAttachment/$HasNoAttachment keywords for "With attachment" search filter (#10053)
  • OAuth: Fix bug where it was impossible to login again after logout (#10073)
  • OAuth: Add oauth_auth_type option
  • Managesieve: Fix handling of string-list format values for date tests in Out of Office (#10075)
  • Password: Extend Dovecot passwdfile driver with dynamic file path support (#10036)
  • Fix a UI issue on using browser Back button after allowing remote resources (#10062)
  • Fix syntax error in DDL scripts for Postgres (#10070)
  • Security: Fix remote image blocking bypass via SVG content reported by nullcathedral [CVE-2026-25916]
  • Security: Fix CSS injection vulnerability reported by CERT Polska [CVE-2026-26079]

Release 1.7-rc2

  • Fix syntax error in DDL scripts for Postgres (#10052)
  • Security: Fix Cross-Site-Scripting vulnerability via SVG's animate tag [CVE-2025-68461]
  • Security: Fix Information Disclosure vulnerability in the HTML style sanitizer [CVE-2025-68460]
  • Support $HasAttachment/$HasNoAttachment keywords for "With attachment" search filter (#10053)

Release 1.7-rc

  • Move autocomplete list rendering to client-side (#9832)
  • Remove contact_search_name option in favor of contactlist_name_template (#9832)
  • Add scope parameter to contact search (#9863)
  • Add tooltip with folder name to widescreen list of multi-folder listing (#9989, #7950)
  • Add ability to chose from all available contact fields on CSV import (#9419)
  • Add a new plugin called markdown_editor that provides an alternative editor to compose emails using Markdown syntax
  • Allow links with "target" attribute in signatures and stored responses (#10017)
  • Preserve requested url on OIDC login (#10033)
  • Managesieve: Show a warning when actions in wrong order (#10015, #6590)
  • Password: Removed the (insecure) virtualmin driver (#8007)
  • Fix jqueryui plugin's minicolors.css issue with custom skins (#9967)
  • Fix skin_logo with a relative URL (#10030)
  • Replace session attribute changed by expires_at to allow for variable session lengths per-user.
  • Add rel='noopener' to all links opening in a new window to mitigate against misuse in older browsers.

Release 1.7-beta2

  • Support PHP v8.5(-pre) without deprecation warnings.
  • Support IPv6 in database DSN (#9937)
  • Use htmleditor setting also for indentity signature (#9954)
  • Fix regression in handling of non-unicode characters in a plain text message (#9953)
  • Fix parsing of inline styles that aren't well-formatted (#9948)
  • Support early MIME types for S/MIME encrypted messages (#9973)
  • Only apply fix_path for href attrib in s (#9943)
  • Show homograph-warning-icon before email address, unify warning wording (#9945)
  • Show full details with warning icon in case of phishing suspicion (#9945)
  • Prepend group-names to display-name (#9945)
  • Wash the name attribute also on more elements (#9949)
  • Sanitize filename on download (#9960)
  • Drop Internet Explorer from supported browsers (#9963)
  • Enforce leading backslash for non-namespaced non-Roundcube uses (#9935)
  • Use asset_url() instead of get_skin_file() for deleteicon on contact edit form (#9933)
  • Several changes to the test tooling.

Release 1.7-beta

  • Set minimum required PHP version to 8.1 (#9599)
  • Update to jQuery 3.7.1
  • Drop dependency on JsTimeZoneDetect (#8965)
  • Added apcu cache driver (#9828)
  • Removed apc cache driver
  • Renamed composer.json.dist to composer.json (#9279)
  • Make public_html/ entry-point mandatory, all static resources are served via static.php (#9294, #8851)
  • Removed support for MS SQL Server and Oracle (#7854)
  • Added more strict code quality/style validation
  • Added text/markdown mail rendering (#8873)
  • Store uploads metadata in a separate sql database table instead of a session (#8415)
  • Mouse-over menu on messages list (#7141)
  • Advanced mail search syntax with more possibilities (without UI) (#8502)
  • Added an option for a default mail search scope (#9077, #7556)
  • Added an option for default "Keep formatting" state, option can be hidden via dont_override (#8987, #9703)
  • Added option to define font list and font-size list for HTML editor - available_fonts/available_font_sizes (#5700)
  • IMAP: Support for HAproxy protocol header in IMAP connections (#8625)
  • Change 'smtp_log' option default value to False
  • Add 'php' logging driver (#6138)
  • Delete messages directly from Junk on folder purge if delete_junk is enabled (#8766)
  • Hide information about quota, when there is no quota (#8994)
  • Set timeout=30, connect_timeout=5, read_timeout=120 as defaults for HTTP client (#8865)
  • Remove use of utf8_encode() and utf8_decode() functions deprecated in PHP 8.2
  • Support PHP Zip extension and 7z in install-jsdeps.sh (#8935)
  • Add identities management script - bin/identity.sh (#8887)
  • Add skin information into the About dialog (#9441)
  • Prefer 8bit over quoted-printable for HTML parts, when force_7bit is disabled (#8477)
  • Convert images in HTML content pasted into HTML editor to data: URIs (and later to attachments) (#6938)
  • Add possibility to change ATTR_EMULATE_PREPARES via config file (#9213)
  • Use draft settings (like DSN) on "Edit as new" (#9349)
  • Add more detailed feedback on vCard import errors (#9591)
  • Use new HTML5 parser available on PHP >= 8.4
  • Clear "list is empty" message on loading a new list (#9006)
  • Add enable_autolink option for HTML editor (#9818, #9762)
  • Rework/fix zoom and rotate of attached images (#9843, #7669)
  • Installer: Show NOT OK if none of the database extensions is installed (#9594, #9604)
  • Plugin API: Added message_delete hook (#9499)
  • Plugin API: Added message_move hook (#9499)
  • Mailvelope: Add a button to enable the extension for webmail domain (#9498)
  • OAuth: Add support for SMTP without authentication (#9183)
  • OAuth: Add support for OAuth/OpenIDC discovery (#8201)
  • OAuth: Add support for invalidating the OAuth-session on logout (#8057)
  • OAuth: Add support for OpenID Connect RP-Initiated Logout (#9109)
  • OAuth: Add support for OpenID Connect Back-Channel Logout (#9110)
  • OAuth: Add support for PKCE (#8757)
  • OAuth: Add support for OAUTHBEARER (#9217)
  • OAuth: Add oauth_debug option (#9217)
  • OAuth: Fix: missing config oauth_provider_name in rcmail_oauth's constructor (#9217)
  • OAuth: Fix Bearer authentication for Kinde (#9244)
  • OAuth: Refactor: move display to the rcmail_oauth class and use loginform_content hook (#9217)
  • OAuth: Add a flag to the 'authenticate' hook arguments indicating SSO is in use
  • Additional_Message_Headers: Added %u, %d and %l variables (#8746, #8732)
  • ACL: Set default of 'acl_specials' option to ['anyone'] (#8911)
  • Enigma: Support Kolab's Web Of Anti-Trust feature (#8626)
  • Enigma: Add key icon to passphrase input (#9894)
  • Managesieve: Support :encodeurl (RFC 5435) (#8917)
  • Managesieve: Add List-ID to the list of headers for creating new sieve-filters (#8307)
  • Managesieve: Support an array in managesieve_host option (#9447)
  • Managesieve: Fix the frontend datetime picker not respecting the 12h format and apending a dangling 's' to the seconds (#9688)
  • Managesieve: Add parsing for all PHP time formatters from time_format config to frontend the time picker (#9655)
  • Password: Add ldap_samba_ad driver (#8525)
  • Password: Allow LDAP access using LDAP URI and SASL binding (#8402)
  • Password: Use Guzzle HTTP Client in the pwned driver
  • Password: Use Guzzle HTTP Client in the directadmin driver
  • Password: Use Guzzle HTTP Client in the plesk driver
  • Password: Use Guzzle HTTP Client in the modoboa driver
  • Password: Use Guzzle HTTP Client in the domainfactory driver
  • Password: Use Guzzle HTTP Client in the cpanel driver
  • Password: Check that a user email is part of password in the zxcvbn checker (#9404)
  • Virtuser_file: Support opensmtpd file format (#9898)
  • Zipdownload: Change "Download..." menu label into "Export..." (#9713)
  • Fix bug in handling rcmail::format_date()'s $convert argument (#9666)
  • Fix use of Bootstrap's box-sizing inside a HTML message content (#9727)
  • Fix folders hierarchy when special folders are subfolders of INBOX, with no personal namespace prefix (#9452)
  • Fix attachment name decoding when 'charset' parameter exists in the headers (#9376)
  • Fix deprecated (in PHP 8.4) use of session_set_save_handler() (#9060)
  • Fix potential HTTP protocol version mismatch (#8982)
  • Fix "Assign to group" action state after creation of a first group (#9889)
  • Fix bug where contacts search would fail if contactlist_fields contained vcard fields (#9850)
  • Fix bug where an mbox export file could include inconsistent message delimiters (#9879)

Release 1.6.11

  • Managesieve: Fix match-type selector (remove unsupported options) in delete header action (#9610)
  • Improve installer to fix confusion about disabling SMTP authentication (#9801)
  • Fix PHP warning in index.php (#9813)
  • OAuth: Fix/improve token refresh
  • Fix dark mode bug where wrong colors were used for blockquotes in HTML mail preview (#9820)
  • Fix HTML message preview if it contains floating tables (#9804)
  • Fix removing/expiring redis/memcache records when using a key prefix
  • Fix bug where a wrong SPECIAL-USE folder could have been detected, if there were more than one per-type (#9781)
  • Fix a default value and documentation of password_ldap_encodage option (#9658)
  • Remove mobile/floating Create button from the list in Settings > Folders (#9661)
  • Fix Delete and Empty buttons state while creating a folder (#9047)
  • Fix connecting to LDAP using ldapi:// URI (#8990)
  • Fix cursor position on "below the quote" reply in HTML mode (#8700)
  • Fix bug where attachments with content type of application/vnd.ms-tnef were not parsed (#7119)
  • Fix Post-Auth RCE via PHP Object Deserialization reported by firs0v [CVE-2025-49113]

Release 1.6.10

  • IMAP: Partial support for ANNOTATE-EXPERIMENT-1 extension (RFC 5257)
  • OAuth: Support standard authentication with short-living password received with OIDC token (#9530)
  • Fix PHP warnings (#9616, #9611)
  • Fix whitespace handling in vCard line continuation (#9637)
  • Fix current script state after initial scripts creation in managesieve_kolab_master mode
  • Fix rcube_imap::get_vendor() result (and PHP warning) on Zimbra server (#9650)
  • Fix regression causing inline SVG images to be missing in mail preview (#9644)
  • Fix plugin "virtuser_file" to handle backward slashes in username (#9668)
  • Fix PHP fatal error when parsing some malformed BODYSTRUCTURE responses (#9689)
  • Fix insert_or_update() and reading database server config on PostgreSQL (#9710)
  • Fix Oauth issues with use_secure_urls=true (#9722)
  • Fix handling of binary mail parts (e.g. PDF) encoded with quoted-printable (#9728)
  • Fix links in comments and config to https:// where available (#9759, #9756)
  • Fix decoding of attachment names encoded using both RFC2231 and RFC2047 standards (#9725)

Release 1.6.9

  • Fix regression where printing/scaling/rotating image attachments was broken (#9571)
  • Fix regression where HTML messages were displayed unstyled (#9586)

Release 1.6.8

  • Managesieve: Protect special scripts in managesieve_kolab_master mode
  • Fix newmail_notifier notification focus in Chrome (#9467)
  • Fix fatal error when parsing some TNEF attachments (#9462)
  • Fix double scrollbar when composing a mail with many plain text lines (#7760)
  • Fix decoding mail parts with multiple base64-encoded text blocks (#9290)
  • Fix bug where some messages could get malformed in an import from a MBOX file (#9510)
  • Fix invalid line break characters in multi-line text in Sieve scripts (#9543)
  • Fix bug where "with attachment" filter could fail on some fts engines (#9514)
  • Fix bug where an unhandled exception was caused by an invalid image attachment (#9475)
  • Fix bug where a long subject title could not be displayed in some cases (#9416)
  • Fix infinite loop when parsing malformed Sieve script (#9562)
  • Fix bug where imap_conn_option's 'socket' was ignored (#9566)
  • Fix XSS vulnerability in post-processing of sanitized HTML content [CVE-2024-42009]
  • Fix XSS vulnerability in serving of attachments other than HTML or SVG [CVE-2024-42008]
  • Fix information leak (access to remote content) via insufficient CSS filtering [CVE-2024-42010]

Release 1.6.7

  • Makefile: Use phpDocumentor v3.4 for the Framework docs (#9313)
  • Fix bug where HTML entities in URLs were not decoded on HTML to plain text conversion (#9312)
  • Fix bug in collapsing/expanding folders with some special characters in names (#9324)
  • Fix PHP8 warnings (#9363, #9365, #9429)
  • Fix missing field labels in CSV import, for some locales (#9393)
  • Fix command injection via crafted im_convert_path/im_identify_path on Windows [CVE-2024-37385]
  • Fix cross-site scripting (XSS) vulnerability in handling list columns from user preferences [CVE-2024-37384]
  • Fix cross-site scripting (XSS) vulnerability in handling SVG animate attributes [CVE-2024-37383]

Release 1.6.6

  • Fix regression in handling LDAP search_fields configuration parameter (#9210)
  • Enigma: Fix finding of a private key when decrypting a message using GnuPG v2.3
  • Fix page jump menu flickering on click (#9196)
  • Update to TinyMCE 5.10.9 security release (#9228)
  • Fix PHP8 warnings (#9235, #9238, #9242, #9306)
  • Fix saving other encryption settings besides enigma's (#9240)
  • Fix unneeded php command use in installto.sh and deluser.sh scripts (#9237)
  • Fix TinyMCE localization installation (#9266)
  • Fix bug where trailing non-ascii characters in email addresses could have been removed in recipient input (#9257)
  • Fix IMAP GETMETADATA command with options - RFC5464

Release 1.6.5

  • Fix PHP8 fatal error when parsing a malformed BODYSTRUCTURE (#9171)
  • Fix duplicated Inbox folder on IMAP servers that do not use Inbox folder with all capital letters (#9166)
  • Fix PHP warnings (#9174)
  • Fix UI issue when dealing with an invalid managesieve_default_headers value (#9175)
  • Fix bug where images attached to application/smil messages weren't displayed (#8870)
  • Fix PHP string replacement error in utils/error.php (#9185)
  • Fix regression where smtp_user did not allow pre/post strings before/after %u placeholder (#9162)
  • Fix cross-site scripting (XSS) vulnerability in setting Content-Type/Content-Disposition for attachment preview/download [CVE-2023-47272]

Release 1.6.4

  • Fix PHP8 warnings (#9142, #9160)
  • Fix default 'mime.types' path on Windows (#9113)
  • Managesieve: Fix javascript error when relational or spamtest extension is not enabled (#9139)
  • Fix cross-site scripting (XSS) vulnerability in handling of SVG in HTML messages [CVE-2023-5631] (#9168)

Release 1.6.3

  • Fix bug where installto.sh/update.sh scripts were removing some essential options from the config file (#9051)
  • Update jQuery-UI to version 1.13.2 (#9041)
  • Fix regression that broke use_secure_urls feature (#9052)
  • Fix potential PHP fatal error when opening a message with message/rfc822 part (#8953)
  • Fix bug where a duplicate <title> tag in HTML email could cause some parts being cut off (#9029)
  • Fix bug where a list of folders could have been sorted incorrectly (#9057)
  • Fix regression where LDAP addressbook 'filter' option was ignored (#9061)
  • Fix wrong order of a multi-folder search result when sorting by size (#9065)
  • Fix so install/update scripts do not require PEAR (#9037)
  • Fix regression where some mail parts could have been decoded incorrectly, or not at all (#9096)
  • Fix handling of an error case in Cyrus IMAP BINARY FETCH, fallback to non-binary FETCH (#9097)
  • Fix PHP8 deprecation warning in the reconnect plugin (#9083)
  • Fix "Show source" on mobile with x_frame_options = deny (#9084)
  • Fix various PHP warnings (#9098)
  • Fix deprecated use of ldap_connect() in password's ldap_simple driver (#9060)
  • Fix cross-site scripting (XSS) vulnerability in handling of linkrefs in plain text messages [CVE-2023-43770]

Release 1.6.2

  • Add Uyghur localization
  • Fix regression in OAuth request URI caused by use of REQUEST_URI instead of SCRIPT_NAME as a default (#8878)
  • Fix bug where false attachment reminder was displayed on HTML mail with inline images (#8885)
  • Fix bug where a non-ASCII character in app.js could cause error in javascript engine (#8894)
  • Fix JWT decoding with url safe base64 schema (#8890)
  • Fix bug where .wav instead of .mp3 file was used for the new mail notification in Firefox (#8895)
  • Fix PHP8 warning (#8891)
  • Fix support for Windows-31J charset (#8869)
  • Fix so LDAP VLV option is disabled by default as documented (#8833)
  • Fix so an email address with name is supported as input to the managesieve notify :from parameter (#8918)
  • Fix Help plugin menu (#8898)
  • Fix invalid onclick handler on the logo image when using non-array skin_logo setting (#8933)
  • Fix duplicate recipients in "To" and "Cc" on reply (#8912)
  • Fix bug where it wasn't possible to scroll lists by clicking middle mouse button (#8942)
  • Fix bug where label text in a single-input dialog could be partially invisible in some locales (#8905)
  • Fix bug where LDAP (fulltext) search didn't work without 'search_fields' in config (#8874)
  • Fix extra leading newlines in plain text converted from HTML (#8973)
  • Fix so recipients with a domain ending with .s are allowed (#8854)
  • Fix so vCard output does not contain non-standard/redundant TYPE=OTHER and TYPE=INTERNET (#8838)
  • Fix QR code images for contacts with non-ASCII characters (#9001)
  • Fix PHP8 warnings when using list_flags and list_cols properties by plugins (#8998)
  • Fix bug where subfolders could loose subscription on parent folder rename (#8892)
  • Fix connecting to LDAP using an URI with ldapi:// scheme (#8990)
  • Fix insecure shell command params handling in cmd_learn driver of markasjunk plugin (#9005)
  • Fix bug where some mail headers didn't work in cmd_learn driver of markasjunk plugin (#9005)
  • Fix PHP fatal error when importing vcf file using PHP 8.2 (#9025)
  • Fix so output of log_date_format with microseconds contains time in server time zone, not UTC

Release 1.6.1

  • Terminate session if refreshing oauth token fails (#8734)
  • Fix various PHP 8.1 warnings (#8628, #8644, #8667, #8656, #8647)
  • Password: Remove references to %c variable that has been removed before (#8633)
  • Fix anchor links in HTML mail (#8632)
  • Fix bug where config creation in Installer did ignore options in the form (#8634)
  • Fix bug where renamed options were removed from the config on installto.sh (update.sh) run (#8643)
  • Fix favicon rewrite rule in .htaccess (#8654)
  • Fix various PHP 8.2 warnings
  • Fix bug where it wasn't possible to create more than one response record on SQLite and Postgres (#8664)
  • Fix support for ManageSieve over implicit SSL (#8670)
  • Fix bug where "about:blank" page could trigger "load error" (#8554)
  • Fix bug where setting 'Clear Trash on Logout' to 'all messages' didn't work (#8687)
  • Fix bug where the attachment menu wouldn't disappear after an action is selected (#8691)
  • Fix bug where some dialogs in an eml attachment preview would not close on mobile (#8627)
  • Fix bug where multiline data&colon;image URI's in emails were stripped from the message on display (#8613)
  • Fix fatal error on identity page if Enigma plugin is misconfigured (#8719)
  • Fix so N property always exists in a vCard export (#8771)
  • Fix authenticating to Courier IMAP with passwords containing a '~' character (#8772)
  • Fix handling of smtp/imap port options on configuration file update (#8756)
  • Fix bug where array values could not be saved in utils/save_pref action (#8781)
  • Add workaround for using Roundcube behind a reverse proxy with a subpath: 'request_path' option (#8738, #8770)
  • Fix bug where "Invalid skin name" error was logged on preferences save if there's only one skin (#8825)
  • Fix SIGBUS raised in ImageMagick when more than one process tried to generate a thumbnail of the same image attachment (#8511)
  • Fix bug where updater does not update the vendor packages (#8642)
  • Fix missing mail composing textarea on reply/draft with a long plain text content (#8866)

Release 1.6.0

  • Fix SMTP XCLIENT extension when not using STARTTLS (#8581)
  • Fix call to undefined method rcube_ldap_generic::option_set() (#8564)
  • Fix PHP Fatal error on incompatible method declaration of rcmail_output_json::command() and rcmail_output::command() (#8579)
  • Fix support for DSN specification without host e.g. pgsql:///dbname (#8558)
  • Fix TinyMCE configuration for handling styles of pasted content in webkit browsers (#8555)
  • Fix bug where some checkboxes could be selected unintentinally (#8565)
  • Fix css styles of the email recipient element while dragging (#8580)
  • Fix PHP 8.1 warnings in the LDAP backend code (#8572)
  • Fix various PHP 8.1 warnings (#8584)
  • Fix bug where a recipient address containing UTF-8 characters was ignored when sending an email (#8493, #8546)
  • Fix so rcmail::contact_exists() works with IDNA addresses (#8545)
  • Fix password option in storage_init hook after refreshing oauth access token (#8436)
  • Fix attachment Options popover menu after attachment delete (#8602)
  • Fix so "Found unconstructed Spoofchecker" error is not fatal (#8537)

Release 1.6-rc

  • Update to jQuery-UI 1.13.1 (#8455)
  • Added possibility to make the logo image a link via the 'skin_logo' option (#8501)
  • Use navigator.pdfViewerEnabled for PDF viewer detection
  • Remove use of unreliable charset detection (#8344)
  • Don't list images attached to multipart/related part as attachments (#7184)
  • Password: Add support for ssha256 algorithm (#8459)
  • Fix so unix:// URI is supported in various host spec. options again (#8468)
  • Fix slow loading of long HTML content into the HTML editor (#8108)
  • Fix bug where SMTP password didn't work if it contained '%p' (#8435)
  • Enigma: Fix initial synchronization of private keys
  • Enigma: Fix double quoted-printable encoding of pgp-signed messages with no attachments (#8413)
  • Fix handling of message/rfc822 parts that are small and are multipart structures with a single part (#8458)
  • Fix bug where session could time out if DB and PHP timezone were different (#8303)
  • Fix bug where DSN flag state wasn't stored with a draft (#8371)
  • Fix broken encoding of HTML content encapsulated in a RTF attachment (#8444)
  • Fix problem with aria-hidden=true on toolbar menus in the Elastic skin (#8517)
  • Fix so links (e.g. www.some.page or http://some.page) are not considered mispellings (#8527)
  • Fix bug where title tag content was displayed in the body if it contained HTML tags (#8540)

Release 1.6-beta

  • Unified and simplified services connection options (#8310):
    1. IMAP:
      • renamed default_host to imap_host
      • removed default_port option (non-standard port can be set via imap_host)
      • set "localhost:143" as a default for imap_host
    2. SMTP:
      • renamed smtp_server to smtp_host
      • removed smtp_port option (non-standard port can be set via smtp_host)
      • set "localhost:587" as a default for smtp_host
    3. LDAP:
      • removed port option from ldap_public array (non-standard port can be set via host)
      • removed use_tls option from ldap_public array (use tls:// prefix in host)
    4. Managesieve:
      • removed managesieve_port option (non-standard port can be set via managesieve_host)
      • removed managesieve_usetls option (tls:// prefix in managesieve_host have to be used)
  • Plugin API: Removed smtp_port parameter in smtp_connect hook
  • Plugin API: Renamed smtp_server parameter to smtp_host in smtp_connect hook
  • Plugin API: Removed port parameter in managesieve_connect hook
  • Plugin API: Removed usetls parameter in managesieve_connect hook
  • Added support for PHP 8.1 (#8151)
  • Dropped support for PHP < 7.3 (#7976)
  • Dropped support for strftime-like format (with % sign) in date and time format configuration
  • Moved the Classic and Larry skins to their own repository (#8271)
  • SQLite: Use foreign keys, require SQLite >= 3.6.19
  • Replace Endroid QrCode with BaconQrCode (#8173)
  • Support responses (snippets) in HTML format (#5315)
  • Purge also subfolders of Trash (and/or messages in them) on logout (#1037)
  • Add support for encryption with AEAD ciphers, e.g. aes-256-gcm (#7097)
  • Add option to purge deleted mails older than 30, 60 or 90 days (#5493)
  • Add ability to mark multiple messages as not deleted at once (#5133)
  • Add possibility to disable line-wrapping of sent mail body (#5101)
  • Improve/Fix wrapping of plain text messages on preview and reply (#6974, #8391, #8378, #8289)
  • Improve searching by sender/recipient headers, support Reply-To and Followup-To (#6582)
  • Add option to control links handling behavior on html to text conversion (#6485)
  • Add 'loginform_content' plugin hook (#8273, #6569)
  • SMTP: If requested use TLS also without authentication (#4590, #8111)
  • Display a generic error page on initial DB/configuration errors (#8222)
  • Display telephone numbers as tel: links (#8240)
  • Elastic: Move scrollbar settings to variables (#8352)
  • Elastic: Use thin scrollbars in both light and dark mode
  • Elastic: Make the scrollbar color lighter in dark mode (#8345)
  • Autologout: A new plugin to auto log out users with a POST request (#8270)
  • Enigma: Upgrade to OpenPGP.js v5.0
  • Identicon: Make background color of the image to match the current skin colors (#8256)
  • Newmail_notifier: Update favicon to match the current favicon style and size (#7826)
  • Password: Remove password_blowfish_cost option, in favor of password_algorithm_options
  • Password: Remove support for password_algorithms crypt, hash and cram-md5
  • Password: Remove support for %c, %d, %n, %q variables in password_query
  • Password: Add support for passwords based on PHP's password_hash() function (#7724)
  • Password: Verify current password with IMAP (#8142)
  • Password: Improve handling errors on executed commands (#8200)
  • Password: Add Mailcow driver (#8291)
  • Fix compatibility with Referrer-Policy: "strict-origin" (#8170)
  • Fix locked SQLite database for the CLI tools (#8035)
  • Fix Makefile on Linux (#8211)
  • Fix so PHP warnings are ignored when resizing a malformed image attachment (#8387)
  • Fix various PHP8 warnings (#8392, #9193)
  • Fix mail headers injection via the subject field on mail compose (#8404)
  • Fix bug where small message/rfc822 parts could not be decoded (#8408)
  • Fix setting HTML mode on reply/forward of a signed message (#8405)
  • Fix handling of RFC2231-encoded attachment names inside of a message/rfc822 part (#8418)
  • Fix bug where some mail parts (images) could have not be listed as attachments (#8425)
  • Fix bug where attachment icons were stuck at the top of the messages list in Safari (#8433)

Release 1.5.2