Количество 6
Количество 6
CVE-2026-48846
In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, the remote image blocking feature can be bypassed via a crafted CSS var() value in an e-mail message, which may lead to information disclosure or access-control bypass.
CVE-2026-48846
In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, the remote image blocking feature can be bypassed via a crafted CSS var() value in an e-mail message, which may lead to information disclosure or access-control bypass.
CVE-2026-48846
In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, the r ...
GHSA-xx87-33v7-6x23
In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, the remote image blocking feature can be bypassed via a crafted CSS var() value in an e-mail message, which may lead to information disclosure or access-control bypass.
BDU:2026-07444
Уязвимость почтового клиента RoundCube Webmail, связанная с отсутствием проверки корректности принимаемых запросов, позволяющая нарушителю раскрыть защищаемую информацию или обойти существующие механизмы безопасности
openSUSE-SU-2026:20852-1
Security update for roundcubemail
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-48846 In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, the remote image blocking feature can be bypassed via a crafted CSS var() value in an e-mail message, which may lead to information disclosure or access-control bypass. | CVSS3: 6.5 | 0% Низкий | 2 месяца назад | |
CVE-2026-48846 In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, the remote image blocking feature can be bypassed via a crafted CSS var() value in an e-mail message, which may lead to information disclosure or access-control bypass. | CVSS3: 6.5 | 0% Низкий | 2 месяца назад | |
CVE-2026-48846 In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, the r ... | CVSS3: 6.5 | 0% Низкий | 2 месяца назад | |
GHSA-xx87-33v7-6x23 In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, the remote image blocking feature can be bypassed via a crafted CSS var() value in an e-mail message, which may lead to information disclosure or access-control bypass. | CVSS3: 6.5 | 0% Низкий | 2 месяца назад | |
BDU:2026-07444 Уязвимость почтового клиента RoundCube Webmail, связанная с отсутствием проверки корректности принимаемых запросов, позволяющая нарушителю раскрыть защищаемую информацию или обойти существующие механизмы безопасности | CVSS3: 6.5 | 0% Низкий | 2 месяца назад | |
openSUSE-SU-2026:20852-1 Security update for roundcubemail | 2 месяца назад |
Уязвимостей на страницу