← Späť na vyhľadávanie CVE

CVE-2026-48848

Roundcube Webmail

Popis

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7 has insufficient HTML sanitization that could lead to Cascading Style Sheets (CSS) injection via an SVG document that has an animate element with the attributeName attribute.

CVSS 7.2EPSS 0.388%Riziko 0.75
Zobraziť zdroj
Zverejnené
2026-05-25 20:16:37
Dotknuté verzie
<1.6.16, <1.7
Typ
Webová aplikácia
Vektor
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N