<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>WildforTech Security Advisories — Roundcube</title><description>Actively exploited vulnerabilities affecting Roundcube products.</description><link>https://wildfortech.com</link><atom:link href="https://wildfortech.com/security/vendor/roundcube.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2025-49113 — RoundCube Webmail Deserialization of Untrusted Data Vulnerability</title><link>https://wildfortech.com/security#CVE-2025-49113</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2025-49113</guid><description>RoundCube Webmail contains a flaw where the &apos;_from&apos; parameter in a URL is not validated during file uploads, allowing any authenticated user to trigger deserialization of untrusted data and achieve remote code execution on the server. This means an attacker with only a standard webmail login can potentially take full control of the underlying system — no admin privileges required. Organizations running RoundCube as their webmail platform are directly at risk of server compromise.</description><pubDate>Fri, 20 Feb 2026 00:00:00 GMT</pubDate><category>Roundcube</category><category>Webmail</category></item><item><title>CVE-2025-68461 — RoundCube Webmail Cross-site Scripting Vulnerability</title><link>https://wildfortech.com/security#CVE-2025-68461</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2025-68461</guid><description>This flaw allows attackers to inject malicious scripts into RoundCube Webmail by embedding JavaScript inside an SVG document&apos;s animate tag. Because webmail runs in the browser and handles untrusted email content, a successful exploit could let an attacker hijack a user&apos;s session, steal credentials, or perform actions on their behalf — all without any interaction beyond opening a crafted email. RoundCube is widely deployed in enterprise and hosting environments, making this a high-value target.</description><pubDate>Fri, 20 Feb 2026 00:00:00 GMT</pubDate><category>Roundcube</category><category>Webmail</category></item><item><title>CVE-2024-42009 — RoundCube Webmail Cross-Site Scripting Vulnerability</title><link>https://wildfortech.com/security#CVE-2024-42009</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2024-42009</guid><description>This cross-site scripting flaw in Roundcube Webmail allows an attacker to craft a malicious email that, when viewed by a victim, exploits a desanitization bug in the mail display code. The practical result is serious: an attacker can silently steal the victim&apos;s emails or send emails on their behalf without any interaction beyond opening the message. Because Roundcube is widely used in enterprise and government environments, this flaw poses a significant risk of credential theft and data exfiltration.</description><pubDate>Mon, 09 Jun 2025 00:00:00 GMT</pubDate><category>Roundcube</category><category>Webmail</category></item></channel></rss>