CVE-2023-5631: Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability
Medium severity, CVSS 5.4. Actively exploited: in CISA KEV since 2023-10-26. EPSS: 75.9% chance of exploitation in the next 30 days.
Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a crafted SVG document because of program/lib/Roundcube/rcube_washtml.php behavior. This could allow a remote attacker to load arbitrary JavaScript code.
Affected products
- Debian Debian Linux: version 10.0 only; version 11.0 only; version 12.0 only
- Fedoraproject Fedora: version 39 only
- Roundcube Webmail: before 1.4.15 (fixed in 1.4.15); from 1.5.0, before 1.5.5 (fixed in 1.5.5); from 1.6.0, before 1.6.4 (fixed in 1.6.4)
Published 2023-10-18. Last modified 2026-06-17.