← Back to browse · API

CVE-2025-68461

Severity
HIGH
CVSS
7.2
EPSS
0.20506
Risk score
60.98
CISA KEV
Yes
PoC
No
Published
2025-12-18
Modified
2026-02-26
First seen
2026-08-07
Aliases
EUVD-2025-204035, GHSA-QQRG-HPXX-MMVW
Products
Roundcube:Webmail, bulwarkmail:Webmail 0 <1.5.12, bulwarkmail:Webmail 1.6.0 <1.6.12
Sources
cisa.gov CVE-2025-68461
euvd EUVD-2025-204035

Description

Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document.

References