Roundcube Product Security Update Advisory (CVE-2025-68461)

Roundcube Product Security Update Advisory (CVE-2025-68461)

Overview

 

We have released a security update to fix vulnerabilities in Roudcube products. users of affected products are advised to update to the latest version.
 

 

Affected Products

 

CVE-2025-68461

 

Roundcube Versions: 1.5.12 and earlier
Roundcube Version: 1.6.12 and earlier

 

 

Resolved Vulnerabilities

 

Cross-site scripting vulnerability in Roundcube Webmail (CVE-2025-68461)

 

 

Vulnerability Patches

vulnerability Patches have been made available in the latest update. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.

 

CVE-2025-68461

 

Roundcube Version: 1.5.12
Roundcube Version: 1.6.12

 

 

references

 

[1] Security updates 1.6.12 and 1.5.12 released
https://roundcube.net/news/2025/12/13/security-updates-1.6.12-and-1.5.12