← Back to CVE List
Vulnerability Intelligence Report
Roundcube Webmail Cross-Site Scripting (XSS) Vulnerability

CVE-2020-13965

An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is among the allowed types for a preview.

CISA KEV SSVC: Active Exploitation
CVSS Base Score
6.3
MEDIUM
Exploitability:2.9
Impact Score:3.4
EPSS Probability:76.60%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-80 ↗CWE-80 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)

Affected Products & Versions

Vendor Product Affected Versions
roundcube webmail all
debian debian_linux 9.0, 10.0
fedoraproject fedora 31, 32

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
EPSS Score
76.596%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2020-06-09T00:00:00
Published2020-06-09T02:45:24
Last Updated2025-10-21T23:35:42

LINK COPIED TO CLIPBOARD