CVE-2026-48848 - Roundcube Webmail CSS Injection Vulnerability

General Security Talk, Announcements and News
Post Reply
Starburst-David
Posts: 45
Joined: Wed Feb 11, 2026 8:31 pm

CVE-2026-48848 - Roundcube Webmail CSS Injection Vulnerability

Post by Starburst-David »

CVE ID: CVE-2026-48848
Published: May 25, 2026
Description: Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7 has insufficient HTML sanitization that could lead to Cascading Style Sheets (CSS) injection via an SVG document that has an animate element with the attributeName attribute.
Severity: 7.2 | HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more...
https://cvefeed.io/vuln/detail/CVE-2026-48848
 

POSTREACT(ions) SUMMARY

Post Reply