Cross-Site Scripting Vulnerability in Roundcube Webmail from Roundcube
CVE-2025-68461

7.2HIGH

Key Information:

Vendor

Roundcube

Status
Vendor
CVE Published:
18 December 2025

What is CVE-2025-68461?

Roundcube Webmail is susceptible to a Cross-Site Scripting (XSS) vulnerability, allowing attackers to inject malicious scripts through the animate tag in SVG documents. This could lead to unauthorized actions or information disclosure when users interact with compromised content. It is vital for users of Roundcube Webmail versions prior to 1.5.12 and 1.6.12 to apply the latest security updates to safeguard against potential exploits.

Affected Version(s)

Webmail 0 < 1.5.12

Webmail 1.6.0 < 1.6.12

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-68461 : Cross-Site Scripting Vulnerability in Roundcube Webmail from Roundcube