CVE-2025-68461CISA KEV: Actively Exploited

RoundCube Webmail Cross-site Scripting Vulnerability

Published Feb 20, 2026·Updated Feb 20, 2026

Description

RoundCube Webmail contains a cross-site scripting vulnerability via the animate tag in an SVG document.

Public Exploits & PoCs2 found

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free