CVE-2026-25916: Roundcube Webmail
Medium severity, CVSS 4.3. EPSS: 0.5% chance of exploitation in the next 30 days.
Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13, when "Block remote images" is used, does not block SVG feImage.
Affected products
- Roundcube Webmail: before 1.5.13 (fixed in 1.5.13); from 1.6.0, before 1.6.13 (fixed in 1.6.13)
Published 2026-02-09. Last modified 2026-06-17.