Roundcube Product Security Update Advisory (CVE-2025-68461)
Overview
We have released a security update to fix vulnerabilities in Roudcube products. users of affected products are advised to update to the latest version.
Affected Products
CVE-2025-68461
Roundcube Versions: 1.5.12 and earlier
Roundcube Version: 1.6.12 and earlier
Resolved Vulnerabilities
Cross-site scripting vulnerability in Roundcube Webmail (CVE-2025-68461)
Vulnerability Patches
vulnerability Patches have been made available in the latest update. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.
CVE-2025-68461
Roundcube Version: 1.5.12
Roundcube Version: 1.6.12
references
[1] Security updates 1.6.12 and 1.5.12 released
https://roundcube.net/news/2025/12/13/security-updates-1.6.12-and-1.5.12