Components
Vulnerabilities
Pricing
MCP
Docs
Sign up
Login
Find vulnerabilities. Fix fast with AI.
Search components by package, version, or CVE to get started.
Ecosystem
Package
Version
Vulnerabilities
CVE-2020-13965
CVE-2020-13965
EXPLOITED
An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is among the allowed types for a preview.
Published Oct 22, 2025
https://github.com/DrunkenShells/Disclosures/tree/master/CVE-2020-13965-Cross%20Site-Scripting%20via%20Malicious%20XML%20Attachment-Roundcube
CVSS Score
Medium
6.1
Components Impacted
Components Impacted
Security Details
Security Details
Sonatype Research
Sonatype Research
Ecosystem
Package
Version
Ecosystem
Package
Version
rpm
roundcubemail
0.1.1-4.el4
rpm
roundcubemail
0.1.1-7.el5
rpm
roundcubemail
1.0.12-1.el6
rpm
roundcubemail
1.0.9-4.el6
rpm
roundcubemail
1.1.10-1.el7
rpm
roundcubemail
1.1.12-2.el7
rpm
roundcubemail
1.1.9-1.el7
1-7 of 7
CVE-2020-13965 | Components Impacted | Sonatype Guide | Sonatype Guide