Cross-Site Scripting Vulnerability in Roundcube Webmail from Roundcube
CVE-2025-68461
7.2HIGH
What is CVE-2025-68461?
Roundcube Webmail is susceptible to a Cross-Site Scripting (XSS) vulnerability, allowing attackers to inject malicious scripts through the animate tag in SVG documents. This could lead to unauthorized actions or information disclosure when users interact with compromised content. It is vital for users of Roundcube Webmail versions prior to 1.5.12 and 1.6.12 to apply the latest security updates to safeguard against potential exploits.
Affected Version(s)
Webmail 0 < 1.5.12
Webmail 1.6.0 < 1.6.12
