Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-68461

75
FAUCET Score

CVE-2025-68461 is a Cross-Site-Scripting (XSS) vulnerability affecting Roundcube Webmail versions prior to 1.5.12 and 1.6.12, specifically exploitable via the animate tag in an SVG document. It has a CVSS score of 6.1 (MEDIUM), indicating a network-based attack with low complexity, requiring user interaction, and leading to low impact on confidentiality and integrity. This vulnerability is actively exploited in the wild, as confirmed by its inclusion in CISA's KEV catalog, and has garnered significant community discussion and media coverage, despite no public exploit code being available on common platforms like Metasploit or ExploitDB.

Impacted Technologies

VendorProductVersion(s)CPE
>= 0, < 1.5.12CPE match
cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:*
>= 1.6.0, < 1.6.12CPE match
cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:*
< 1.5.12CPE matchmatch criteria
cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.2HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
2.7
CvssVersion
3.1

Exploit Intelligence

EPSS Score
20.09%
Probability of exploitation in next 30 days
EPSS Percentile
97.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
Added to KEV · Feb 20, 2026
This CVE's current EPSS score of 0.2009 is in the 99th percentile among its peer group of 26,208 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (8)

github_advisorypatch availablevia nvd_reference
View patch
ubuntupatch availablevia ubuntu_usn
Product: roundcube (bionic)Fixed in: 1.3.6+dfsg.1-1ubuntu0.1~esm6
ubuntupatch availablevia ubuntu_usn
Product: roundcube (focal)Fixed in: 1.4.3+dfsg.1-1ubuntu0.1~esm6
ubuntupatch availablevia ubuntu_usn
Product: roundcube (jammy)Fixed in: 1.5.0+dfsg.1-2ubuntu0.1~esm5
ubuntupatch availablevia ubuntu_usn
Product: roundcube (noble)Fixed in: 1.6.6+dfsg-2ubuntu0.1+esm2
3cxvendor investigatingvia llm_extracted
horillavendor investigatingvia llm_extracted
inveniosoftwarevendor investigatingvia llm_extracted

Vendor Advisories (5)

horillallm-horilla-0d81546c16009034MEDIUM

RoundCube Webmail Cross-Site Scripting (CVE-2025-68461)

Mar 23, 2026
inveniosoftwarellm-inveniosoftware-869376dac0b1f869MEDIUM

RoundCube Webmail Cross-Site Scripting (CVE-2025-68461)

Mar 23, 2026
3cxllm-3cx-1c1fc0052aa12e62MEDIUM

RoundCube Webmail Cross-Site Scripting (CVE-2025-68461)

Mar 23, 2026
ubuntuUSN-8097-1

Roundcube Webmail vulnerabilities

Mar 16, 2026
redhatCVE-2025-68461Moderate

roundcubemail: Roundcube Webmail: Cross-Site Scripting (XSS) vulnerability via crafted SVG animate tag

Dec 18, 2025

References

cisa.gov / known-exploited-vulnerabilities-catalog
US Government Resource
github.com / roundcube/roundcubemail/commit/bfa032631c36b900e7444dfa278340b33cbf7cdb
Patch
roundcube.net / news/2025/12/13/security-updates-1.6.12-and-1.5.12
Vendor Advisory