MEDIUM

CVE-2025-68461

Roundcube Webmail 2025-12-18 CVSS v3.1
CVSS
6.1
KEV

Description

Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document.

Summary dbcve.org

Roundcube Webmail versions before 1.5.12 and 1.6.12 fail to properly sanitize SVG documents, specifically the animate tag, allowing authenticated users or attackers who can send emails with SVG attachments to inject malicious JavaScript that executes in the context of the victim's browser session.

Mitigation

Upgrade Roundcube Webmail to version 1.5.12, 1.6.12, or later to patch the SVG XSS vulnerability. If immediate upgrade is not feasible, consider blocking SVG attachments at the mail gateway.

Patch Commit

Weakness (CWE)

CWE-79 Cross-site Scripting (XSS)

EPSS Score

26.84%
Probability of exploitation in next 30 days
97.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE