CVE-2020-16145: Fedoraproject Fedora

Medium severity, CVSS 6.1. EPSS: 2.1% chance of exploitation in the next 30 days.

Roundcube Webmail before 1.3.15 and 1.4.8 allows stored XSS in HTML messages during message display via a crafted SVG document. This issue has been fixed in 1.4.8 and 1.3.15.

Affected products

  • Fedoraproject Fedora: version 31 only; version 32 only
  • Roundcube Webmail: before 1.3.15 (fixed in 1.3.15); from 1.4.0, before 1.4.8 (fixed in 1.4.8)

Published 2020-08-12. Last modified 2026-06-17.