CVE-2016-4068Cross-site Scripting in Webmail

CWE-79Cross-site Scripting15 documents7 sources
Severity
6.1MEDIUMNVD
EPSS
0.4%
top 37.73%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 13
Latest updateMar 30

Description

Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.0.9 and 1.1.x before 1.1.5 allows remote attackers to inject arbitrary web script or HTML via a crafted SVG, a different vulnerability than CVE-2015-8864.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages6 packages

Debianroundcube/roundcube_webmail< 1.2.1+dfsg.1-1+7
Ubunturoundcube/roundcube_webmail< 1.2~beta+dfsg.1-0ubuntu1+esm7+1
NVDroundcube/webmail1.0.8+2
NVDroundcube/roundcube_webmail1.1.1, 1.1.2, 1.1.3+2
NVDopensuse/leap42.1

Patches

🔴Vulnerability Details

7
OSV
roundcube vulnerabilities2026-03-30
GHSA
GHSA-4rqp-f36w-28hw: Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 12022-05-14
GHSA
GHSA-69rv-gvqx-4x9h: Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 12022-05-14
OSV
CVE-2016-4068: Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 12017-04-13
OSV
CVE-2015-8864: Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 12017-04-13

📋Vendor Advisories

3
Ubuntu
Roundcube Webmail vulnerabilities2026-03-30
Debian
CVE-2016-4068: roundcube - Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.0.9 and 1...2016
Debian
CVE-2015-8864: roundcube - Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.0.9 and 1...2015

💬Community

3
Bugzilla
CVE-2015-2181 CVE-2015-8864 CVE-2016-4068 CVE-2016-4069 roundcubemail: security issues fixed in version 1.0.9 [fedora-all]2016-04-25
Bugzilla
CVE-2015-2181 CVE-2015-8864 CVE-2016-4068 CVE-2016-4069 roundcubemail: security issues fixed in version 1.0.92016-04-25
Bugzilla
CVE-2015-2181 CVE-2015-8864 CVE-2016-4068 CVE-2016-4069 roundcubemail: security issues fixed in version 1.0.9 [epel-all]2016-04-25
CVE-2016-4068 — Cross-site Scripting in Webmail | cvebase