ChangeLog: https://github.com/roundcube/roundcubemail/releases/tag/1.4.11 Most notably is the fix of a XSS vulnerability which allowed an attacker to inject malicious code via CSS's `content'-property from an email[1]. [1] https://github.com/roundcube/roundcubemail/commit/9dc276d5f26042db02754fa1bac6fbd683c6d596