Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7 has insufficient HTML sanitization that could lead to Cascading Style Sheets (CSS) injection via an SVG document that has an animate element with the attributeName attribute.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-05-25 20:16
Updated : 2026-07-24 10:10
NVD link : CVE-2026-48848
Mitre link : CVE-2026-48848
CVE.ORG link : CVE-2026-48848
JSON object : View
Products Affected
No product.
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
