Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2016-4068

21
FAUCET Score

CVE-2016-4068 is a cross-site scripting (XSS) vulnerability in Roundcube Webmail versions prior to 1.0.9 and 1.1.5, allowing remote attackers to inject malicious web script or HTML through crafted SVG files. This medium-severity vulnerability (CVSS 6.1) can be exploited with low attack complexity via a network, requiring user interaction, and potentially leading to limited confidentiality and integrity impacts. There is no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
42.1CPE matchmatch criteria
cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*
13.1CPE matchmatch criteria
cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:*
13.2CPE matchmatch criteria
cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*
1.1.1CPE matchmatch criteria
cpe:2.3:a:roundcube:roundcube_webmail:1.1.1:*:*:*:*:*:*:*
1.1.2CPE matchmatch criteria
cpe:2.3:a:roundcube:roundcube_webmail:1.1.2:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

6.1MEDIUM

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
2.8
Impact Score
2.7
CvssVersion
3.0

Exploit Intelligence

EPSS Score
2.48%
Probability of exploitation in next 30 days
EPSS Percentile
82.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0248 is in the 92nd percentile among its peer group of 26,219 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (4)

github_advisorypatch availablevia nvd_reference
View patch
matrixpatch availablevia llm_extracted
View patch
ubuntupatch availablevia ubuntu_usn
Product: roundcube (bionic)Fixed in: 1.3.6+dfsg.1-1ubuntu0.1~esm7
ubuntupatch availablevia ubuntu_usn
Product: roundcube (xenial)Fixed in: 1.2~beta+dfsg.1-0ubuntu1+esm7

Vendor Advisories (2)

ubuntuUSN-8132-1

Roundcube Webmail vulnerabilities

Mar 30, 2026
matrixllm-matrix-274ae49727716c05

Roundcube Webmail vulnerabilities

References

lists.opensuse.org / opensuse-updates/2016-08/msg00078.html
Third Party Advisory
lists.opensuse.org / opensuse-updates/2016-08/msg00079.html
Third Party Advisory
lists.opensuse.org / opensuse-updates/2016-08/msg00095.html
Third Party Advisory
github.com / roundcube/roundcubemail/commit/40d7342dd9c9bd2a1d613edc848ed95a4d71aa18
PatchThird Party Advisory
github.com / roundcube/roundcubemail/issues/4949
Third Party Advisory
github.com / roundcube/roundcubemail/releases/tag/1.0.9
Release NotesThird Party Advisory
github.com / roundcube/roundcubemail/releases/tag/1.1.5
Release NotesThird Party Advisory
github.com / roundcube/roundcubemail/wiki/Changelog
Release NotesThird Party Advisory