Security update 1.5.4 released
We just published a security update to the LTS version 1.5 of Roundcube Webmail. It provides a fix to a recently reported XSS vulnerability:
- Cross-site scripting (XSS) vulnerability in handling of linkrefs in plain text messages, reported by Niraj Shivtarkar.
See the full changelog in the release notes in the release notes on the Github download page.
We strongly recommend to update all productive installations of Roundcube 1.5.x with this new version.Return to News overview