Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7 has insufficient HTML sanitization that could lead to Cascading Style Sheets (CSS) injection via an SVG document that has an animate element with the attributeName attribute.
References
Configurations
No configuration.
History
24 Jul 2026, 10:10
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
25 May 2026, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-25 20:16
Updated : 2026-07-24 10:10
NVD link : CVE-2026-48848
Mitre link : CVE-2026-48848
CVE.ORG link : CVE-2026-48848
JSON object : View
Products Affected
No product.
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
