Description
Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of program/lib/Roundcube/rcube_string_replacer.php behavior.
Remediation
References
Related Vulnerabilities
WordPress 5.5.x Multiple Vulnerabilities (5.5 - 5.5.13)
Apache Tomcat Improper Input Validation Vulnerability (CVE-2012-2733)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-5479)
Drupal Core 9.3.x Security Bypass (9.3.0 - 9.3.5)
WordPress Plugin Social Media Share Buttons & Social Sharing Icons Security Bypass (1.5.1)