CVE-2026-48848

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7 has insufficient HTML sanitization that could lead to Cascading Style Sheets (CSS) injection via an SVG document that has an animate element with the attributeName attribute.
Configurations

No configuration.

History

24 Jul 2026, 10:10

Type Values Removed Values Added
Summary
  • (es) Roundcube Webmail 1.6.x anterior a 1.6.16 y 1.7.x anterior a 1.7 presenta una sanitización HTML insuficiente que podría conducir a la inyección de Hojas de Estilo en Cascada (CSS) a través de un documento SVG que tiene un elemento animate con el atributo attributeName.

25 May 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-25 20:16

Updated : 2026-07-24 10:10


NVD link : CVE-2026-48848

Mitre link : CVE-2026-48848

CVE.ORG link : CVE-2026-48848


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')