PT-2026-43111 · Roundcube · Webmail

Published

2026-05-25

·

Updated

2026-05-25

·

CVE-2026-48848

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7 has insufficient HTML sanitization that could lead to Cascading Style Sheets (CSS) injection via an SVG document that has an animate element with the attributeName attribute.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-48848

Affected Products

Webmail