7.2
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Description
CVE-2025-68461 Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting XSS vulnerability via the animate tag in an SVG document. How does this detection method work? Extracts Roundcube version from the "rcversion" JSON...
Basic Information
ID
E44FCD1C-FC55-56B1-B210-2B9E7A91CD29
Published
Dec 19, 2025 at 11:19
Modified
Dec 19, 2025 at 11:31