CVE-2025-68461 is a Cross-Site-Scripting (XSS) vulnerability affecting Roundcube Webmail versions prior to 1.5.12 and 1.6.12, specifically exploitable via the animate tag in an SVG document. It has a CVSS score of 6.1 (MEDIUM), indicating a network-based attack with low complexity, requiring user interaction, and leading to low impact on confidentiality and integrity. This vulnerability is actively exploited in the wild, as confirmed by its inclusion in CISA's KEV catalog, and has garnered significant community discussion and media coverage, despite no public exploit code being available on common platforms like Metasploit or ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < 1.5.12CPE match | cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:* | ||
>= 1.6.0, < 1.6.12CPE match | cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:* | ||
< 1.5.12CPE matchmatch criteria | cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
RoundCube Webmail Cross-Site Scripting (CVE-2025-68461)
Mar 23, 2026RoundCube Webmail Cross-Site Scripting (CVE-2025-68461)
Mar 23, 2026RoundCube Webmail Cross-Site Scripting (CVE-2025-68461)
Mar 23, 2026Roundcube Webmail vulnerabilities
Mar 16, 2026roundcubemail: Roundcube Webmail: Cross-Site Scripting (XSS) vulnerability via crafted SVG animate tag
Dec 18, 2025