Security update 1.4.13 released

Published: 30 December 2021

We just published a security update to the LTS version 1.4 of Roundcube Webmail. It provides a fix to a recently reported XSS vulnerability:

  • Cross-site scripting (XSS) via HTML messages with malicious CSS content

See the full changelog in the release notes in the release notes on the Github download page.

We strongly recommend to update all productive installations of Roundcube 1.4.x with this new version.

Return to News overview