roundcube is vulnerable to cross-site scripting (XSS). The vulnerability exists through specific CSS token sequences during HTML email rendering which allows an attacker to inject and execute arbitrary javascript.
github.com/roundcube/roundcubemail/commit/9dc276d5f26042db02754fa1bac6fbd683c6d596
lists.fedoraproject.org/archives/list/[email protected]/message/5QPAMYM2DQODSCQIAVNFJR2ETG7WMJOD/
lists.fedoraproject.org/archives/list/[email protected]/message/Q752JPOHTR6H72FK3EIPJZ5O24Z7RGLM/
roundcube.net/news/2021/02/08/security-update-1.4.11
security-tracker.debian.org/tracker/CVE-2021-26925