CVE-2009-0413
RoundCube Webmail <0.2 - XSS
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in RoundCube Webmail (roundcubemail) 0.2 stable allows remote attackers to inject arbitrary web script or HTML via the background attribute embedded in an HTML e-mail message.
References (7)
Scores
EPSS
0.0041
EPSS Percentile
60.8%
Classification
CWE
CWE-79
Status
published
Affected Products (2)
roundcube/webmail
n/a/n/a
Timeline
Published
Feb 03, 2009
Tracked Since
Feb 18, 2026