FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

Roundcube -- Multiple vulnerabilities

Affected packages
roundcube-php82 < 1.6.13,1
roundcube-php83 < 1.6.13,1
roundcube-php84 < 1.6.13,1
roundcube-php85 < 1.6.13,1

Details

VuXML ID f301a241-04d3-11f1-a38c-8447094a420f
Discovery 2026-02-08
Entry 2026-02-08

The Roundcube project reports:

Unspecified CSS injection vulnerability.

Remote image blocking bypass via SVG content.

References

URL https://github.com/roundcube/roundcubemail/releases/tag/1.6.13