Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-48848

Опубликовано: 25 мая 2026
Источник: nvd
CVSS3: 7.2
EPSS Низкий

Описание

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7 has insufficient HTML sanitization that could lead to Cascading Style Sheets (CSS) injection via an SVG document that has an animate element with the attributeName attribute.

EPSS

Процентиль: 32%
0.00388
Низкий

7.2 High

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 7.2
ubuntu
2 месяца назад

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7 has insufficient HTML sanitization that could lead to Cascading Style Sheets (CSS) injection via an SVG document that has an animate element with the attributeName attribute.

CVSS3: 7.2
debian
2 месяца назад

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7 has insuffi ...

CVSS3: 7.2
github
2 месяца назад

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7 has insufficient HTML sanitization that could lead to Cascading Style Sheets (CSS) injection via an SVG document that has an animate element with the attributeName attribute.

CVSS3: 7.2
fstec
3 месяца назад

Уязвимость почтового клиента RoundCube Webmail, связанная с непринятием мер по защите структуры веб-страницы, позволяющая нарушителю выполнить произвольный код

suse-cvrf
2 месяца назад

Security update for roundcubemail

EPSS

Процентиль: 32%
0.00388
Низкий

7.2 High

CVSS3

Дефекты

CWE-79