CVE-2025-68461
Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document.
- Published Dec 18, 2025
- CVSS 6.1 medium
- 26.8% chance of exploitation in the next 30 days (EPSS)
- In CISA's Known Exploited Vulnerabilities catalog
- A fix is available
Affected software
In the news
- Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild The Hacker News ·