A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a crafted e-mail message that abuses a Desanitization issue in message_body() in program/actions/mail/show.php.
https://www.securityweek.com/exploited-vulnerability-impacts-over-80000-roundcube-servers/
https://www.darkreading.com/application-security/poc-code-escalates-roundcube-vuln-threat
https://thehackernews.com/2025/06/cisa-adds-erlang-ssh-and-roundcube.html