OpsBuzz

Alert

RoundCube Webmail Cross-Site Scripting XSS Vulnerability

RoundCube Webmail contains a cross-site scripting XSS vulnerability in the handling of SVG animate attributes that allows a remote attacker to run maliciou

Security · HIGH
Source: CISA Known Exploited VulnerabilitiesMay 2, 2026, 4:51 PMSecurityhigh

Full content

RoundCube Webmail contains a cross-site scripting (XSS) vulnerability in the handling of SVG animate attributes that allows a remote attacker to run malicious JavaScript code.

Vendor: Roundcube

Product: Webmail

Due date: 2024-11-14

Known ransomware use: Unknown

Why it matters

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Related alerts