CVE-2020-35730: Roundcube Webmail Cross-Site Scripting (XSS) Vulnerability

Medium severity, CVSS 6.1. Actively exploited: in CISA KEV since 2023-06-22. EPSS: 32.9% chance of exploitation in the next 30 days.

An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attacker can send a plain text e-mail message, with JavaScript in a link reference element that is mishandled by linkref_addindex in rcube_string_replacer.php.

Affected products

  • Debian Debian Linux: version 9.0 only
  • Fedoraproject Fedora: version 32 only; version 33 only
  • Roundcube Webmail: before 1.2.13 (fixed in 1.2.13); from 1.3.0, before 1.3.16 (fixed in 1.3.16); from 1.4, before 1.4.10 (fixed in 1.4.10)

Published 2020-12-28. Last modified 2026-06-17.