CVE-2025-68461 | Roundcube Webmail up to 1.5.11/1.6.11 SVG Document cross site scripting (Nessus ID 279102 / WID-SEC-2025-2854)
A vulnerability has been found in Roundcube Webmail up to 1.5.11/1.6.11 and classified as problematic. Affected by this issue is some unknown functionality of the component SVG Document Handler. The manipulation leads to cross site scripting.
This vulnerability is documented as CVE-2025-68461. The attack can be initiated remotely. There is not any exploit available.
The affected component should be upgraded.