CVE-2025-68461: RoundCube Webmail Cross-site Scripting Vulnerability
Last updated 30 June 2026
Other sources
Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document.
— NVD
RoundCube Webmail contains a cross-site scripting vulnerability via the animate tag in an SVG document.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/roundcubeto a version that resolves this vulnerability.Fixed in 1.4.15+dfsg.1-1+deb11u9Fixed in 1.6.5+dfsg-1+deb12u8Fixed in 1.6.5+dfsg-1+deb12u9Fixed in 1.6.15+dfsg-0+deb13u1Fixed in 1.6.16+dfsg-0+deb13u1Fixed in 1.6.16+dfsg-1 - Upgrade
Upgrade
Roundcube Webmailto a version that resolves this vulnerability.Fixed in 1.5.12 - Upgrade
Upgrade
Roundcube Webmailto a version that resolves this vulnerability.Fixed in 1.6.12
Event History
Frequently Asked Questions
What is the severity of CVE-2025-68461?
CVE-2025-68461 is classified as a Cross-Site Scripting (XSS) vulnerability that poses moderate risk to users of affected Roundcube Webmail versions.
How do I fix CVE-2025-68461?
To fix CVE-2025-68461, update your Roundcube Webmail to version 1.5.12 or 1.6.12 or later.
Which versions are affected by CVE-2025-68461?
CVE-2025-68461 affects Roundcube Webmail versions prior to 1.5.12 and 1.6 prior to 1.6.12.
What type of vulnerability is CVE-2025-68461?
CVE-2025-68461 is a Cross-Site Scripting (XSS) vulnerability that can lead to unauthorized actions by a malicious actor.
Is my data safe if I use an affected version of Roundcube Webmail due to CVE-2025-68461?
Using an affected version of Roundcube Webmail exposes your data to XSS attacks, which may compromise user confidentiality and safety.