EUVD-2025-204035
Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document.
- EUVD state
- Present in the current official mapping
- Known exploitation
- Recorded by ENISA since 20 Feb 2026. Evidence sources: cisa_kev.
- ENISA score
- 7.2 · CVSS 3.1
- Advisory evidence
- 3 linked advisory records
Only statements that explicitly mention a fix, patch, update, workaround or mitigation are shown here.
- csaf_ncscnl · NCSC-2025-0405Kwetsbaarheid verholpen in Roundcube Webmail
- csaf_opensuse · openSUSE-SU-2026:20323-1Security update for roundcubemail
