logo

Roundcube Vulnerabilities Allow Attackers to Execute Malicious Scripts

ID: 4c3c2fcb-7f94-5238-b2c4-7f9d9f434669

STIX ID: report--4c3c2fcb-7f94-5238-b2c4-7f9d9f434669

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2025-12-19

Date Updated: 2026-04-21

Author: Abinaya

...
...

Roundcube Webmail published critical security updates addressing a high-severity XSS vulnerability (SVG animate tag) and a medium-high information-disclosure bug in the HTML style sanitizer impacting 1.6.x and 1.5.x LTS; administrators are advised to upgrade to 1.6.12 and 1.5.12 immediately to prevent potential session/token theft, credential exposure, and sensitive email data leakage.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.