Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4415-1 | roundcube security update |
Debian DSA |
DSA-6087-1 | roundcube security update |
Ubuntu USN |
USN-8097-1 | Roundcube Webmail vulnerabilities |
Fri, 20 Feb 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
ssvc
|
Fri, 20 Feb 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
kev
|
Thu, 18 Dec 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | roundcubemail: Roundcube Webmail: Cross-Site Scripting (XSS) vulnerability via crafted SVG animate tag | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Thu, 18 Dec 2025 05:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document. | |
| First Time appeared |
Roundcube
Roundcube webmail |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Roundcube
Roundcube webmail |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-02-26T16:07:30.163Z
Reserved: 2025-12-18T05:00:54.176Z
Link: CVE-2025-68461
Updated: 2025-12-18T18:26:29.690Z
Status : Analyzed
Published: 2025-12-18T05:15:56.623
Modified: 2026-02-23T13:24:12.310
Link: CVE-2025-68461
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
Ubuntu USN