Alinto Sogo 5.12.3 is vulnerable to Cross Site Scripting (XSS) via the theme parameter.Referenceshttps://github.com/poblaguev-tot/CVE-2025-63499https://email.example.com/SOGo/so/victim@example.com/Mail/view?theme=%27%3CScRiPt%20%3Ealert%289998%29%3C%2FScRiPt%3E