CVE-2026-48848

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7 has insufficient HTML sanitization that could lead to Cascading Style Sheets (CSS) injection via an SVG document that has an animate element with the attributeName attribute.
Configurations

No configuration.

History

No history.

Information

Published : 2026-05-25 20:16

Updated : 2026-07-24 10:10


NVD link : CVE-2026-48848

Mitre link : CVE-2026-48848

CVE.ORG link : CVE-2026-48848


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')