<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Roundcube security updates 1.4.10, 1.3.16 and 1.2.13 released]]></title><description><![CDATA[<p dir="auto"><a href="https://roundcube.net/news/2020/12/27/security-updates-1.4.10-1.3.16-and-1.2.13" target="_blank" rel="noopener noreferrer nofollow ugc">https://roundcube.net/news/2020/12/27/security-updates-1.4.10-1.3.16-and-1.2.13</a></p>
<blockquote>
<p dir="auto">We just published security updates to the stable version 1.4 and the LTS versions 1.3 and 1.2 of Roundcube Webmail. They all contain fixes to a recently reported stored XSS vulnerability. The 1.4.10 release also contains a few general improvements from our issue tracker.</p>
</blockquote>
<blockquote>
<p dir="auto">Security fix: Stored cross-site scripting (XSS) via HTML or plain text messages with malicious content<br />
Credits for this finding go to Alex Birnberg.</p>
</blockquote>
<blockquote>
<p dir="auto">We strongly recommend to update all productive installations of Roundcube with these new versions.</p>
</blockquote>
<p dir="auto">CHANGELOG for 1.4.10:</p>
<ul>
<li>Fix extra angle brackets in In-Reply-To header derived from mailto: params (#7655)</li>
<li>Fix folder list issue when special folder is a subfolder (#7647)</li>
<li>Fix Elastic's folder subscription toggle in search result (#7653)</li>
<li>Fix state of subscription toggle on folders list after changing folder state from the search result (#7653)</li>
<li>Security: Fix cross-site scripting (XSS) via HTML or plain text messages with malicious content</li>
</ul>
]]></description><link>https://forum.cloudron.io/topic/4076/roundcube-security-updates-1-4-10-1-3-16-and-1-2-13-released</link><generator>RSS for Node</generator><lastBuildDate>Sat, 06 Jun 2026 23:34:33 GMT</lastBuildDate><atom:link href="https://forum.cloudron.io/topic/4076.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 28 Dec 2020 09:03:16 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Roundcube security updates 1.4.10, 1.3.16 and 1.2.13 released on Mon, 28 Dec 2020 15:37:29 GMT]]></title><description><![CDATA[<p dir="auto">Package update is out.</p>
]]></description><link>https://forum.cloudron.io/post/22400</link><guid isPermaLink="true">https://forum.cloudron.io/post/22400</guid><dc:creator><![CDATA[nebulon]]></dc:creator><pubDate>Mon, 28 Dec 2020 15:37:29 GMT</pubDate></item></channel></rss>