Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a information disclosure vulnerability in the HTML style sanitizer.
{
"cna_assigner": "mitre",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/68xxx/CVE-2025-68460.json",
"cwe_ids": [
"CWE-116"
]
}{
"cpe": "cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "1.5.12"
},
{
"introduced": "1.6.0"
},
{
"fixed": "1.6.12"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
]
}