Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-48848

Опубликовано: 25 мая 2026
Источник: debian
EPSS Низкий

Описание

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7 has insufficient HTML sanitization that could lead to Cascading Style Sheets (CSS) injection via an SVG document that has an animate element with the attributeName attribute.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
roundcubefixed1.6.16+dfsg-1package

Примечания

  • https://roundcube.net/news/2026/05/24/security-updates-1.6.16-and-1.7.1

  • https://github.com/roundcube/roundcubemail/commit/58e5263f341e6a418774fb6d2643669a3c4d8a27

EPSS

Процентиль: 32%
0.00388
Низкий

Связанные уязвимости

CVSS3: 7.2
ubuntu
2 месяца назад

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7 has insufficient HTML sanitization that could lead to Cascading Style Sheets (CSS) injection via an SVG document that has an animate element with the attributeName attribute.

CVSS3: 7.2
nvd
2 месяца назад

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7 has insufficient HTML sanitization that could lead to Cascading Style Sheets (CSS) injection via an SVG document that has an animate element with the attributeName attribute.

CVSS3: 7.2
github
2 месяца назад

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7 has insufficient HTML sanitization that could lead to Cascading Style Sheets (CSS) injection via an SVG document that has an animate element with the attributeName attribute.

CVSS3: 7.2
fstec
3 месяца назад

Уязвимость почтового клиента RoundCube Webmail, связанная с непринятием мер по защите структуры веб-страницы, позволяющая нарушителю выполнить произвольный код

suse-cvrf
2 месяца назад

Security update for roundcubemail

EPSS

Процентиль: 32%
0.00388
Низкий