All verified exploits

CVE-2025-68461 Stored XSS via SVG Animate

Deterministic high Roundcube CISA KEV Added cve-verified-cve-2025-68461

Detects vulnerable Roundcube versions where SVG animate tags bypass the HTML sanitizer, allowing stored XSS in email rendering and account takeover.

Is your app exploitable through CVE-2025-68461?

Scan your domain free