MEDIUM
CVE-2025-68461
CVSS
6.1
KEV
Description
Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document.
Summary dbcve.org
Roundcube Webmail versions before 1.5.12 and 1.6.12 fail to properly sanitize SVG documents, specifically the animate tag, allowing authenticated users or attackers who can send emails with SVG attachments to inject malicious JavaScript that executes in the context of the victim's browser session.
Mitigation
Upgrade Roundcube Webmail to version 1.5.12, 1.6.12, or later to patch the SVG XSS vulnerability. If immediate upgrade is not feasible, consider blocking SVG attachments at the mail gateway.
Weakness (CWE)
CWE-79
Cross-site Scripting (XSS)
EPSS Score
26.84%
Probability of exploitation in next 30 days
97.9th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.