CVE-2025-68460: /CVE-2025-68461: Roundcube XSS + I-D prior to 1.5.12/1.6.12
Published Dec 18, 2025
·Updated
Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a information disclosure vulnerability in the HTML style sanitizer.
Affected Software
3 affected components
Roundcube Roundcube Webmail<1.5.12, <1.6.12
Roundcube Webmail<1.5.12
Roundcube Webmail>=1.6.0<1.6.12
Remediation
Event History
Dec 18, 2025
CVE Published
via MITRE·04:54 AM
Data Sourced
via MITRE·04:54 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-68460?
CVE-2025-68460 is classified as an information disclosure vulnerability that can impact user data security.
2
How do I fix CVE-2025-68460?
To mitigate CVE-2025-68460, upgrade to Roundcube Webmail version 1.5.12 or 1.6.12 or later.
3
What versions of Roundcube Webmail are affected by CVE-2025-68460?
CVE-2025-68460 affects Roundcube Webmail versions prior to 1.5.12 and 1.6 prior to 1.6.12.
4
What kind of information can be disclosed due to CVE-2025-68460?
CVE-2025-68460 may allow unauthorized access to user data through effective exploitation of the information disclosure vulnerability.
5
Is CVE-2025-68460 already exploited in the wild?
There is currently no public information indicating that CVE-2025-68460 has been actively exploited in the wild.