Zurück zur CVE-Übersicht
CVE-2026-48849
MEDIUM(4.4)CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N
Risk Signal Score11/100 — NIEDRIG
- CVSS 4.4 — Mittel
Erwähnungen (letzte 60 Tage)
Artikel
EPSS-Score
0.2%
Exploit-Wahrscheinlichkeit (30 Tage)
CVSS Score
4.4
Technische Schwere
Beschreibung
In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, an unsanitized subject field in the draft restored value could lead to stored XSS/HTML/CSS injection on shared mailboxes.
Referenzen
- https://github.com/roundcube/roundcubemail/commit/189d30a4890319cd687df959ca9f76...
- https://github.com/roundcube/roundcubemail/commit/a21519187873ce962db029b6ff68e4...
- https://github.com/roundcube/roundcubemail/releases/tag/1.6.16
- https://github.com/roundcube/roundcubemail/releases/tag/1.7.1
- https://roundcube.net/news/2026/05/24/security-updates-1.6.16-and-1.7.1