Loading market data...
← Back to CVE feed

CVE-2026-48848

HIGH CVSS 7.2 View on NVD ↗

Description

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7 has insufficient HTML sanitization that could lead to Cascading Style Sheets (CSS) injection via an SVG document that has an animate element with the attributeName attribute.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Published: May 25, 2026 20:16 UTC Modified: May 25, 2026 20:16 UTC