CVE 7.2 HIGH

CVE-2026-48848_CVE-2026-48848

7.2 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

Description

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7 has insufficient HTML sanitization that could lead to Cascading Style Sheets (CSS) injection via an SVG document that has an animate element with the attributeName attribute.

Basic Information

ID CVE-2026-48848
Source mitre
Published May 25, 2026 at 19:27

Affected Product

Vendor Roundcube
Product Webmail
Version 1.6.0
Affected Versions Roundcube Webmail 1.6.0
Roundcube Webmail 1.7.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.