In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, an unsanitized subject field in the draft restored value could lead to stored XSS/HTML/CSS injection on shared mailboxes.
Metrics
Affected Vendors & Products
References
History
Mon, 25 May 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Stored XSS via Unvalidated Subject Field in Draft Restoration for Roundcube Webmail |
Mon, 25 May 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, an unsanitized subject field in the draft restored value could lead to stored XSS/HTML/CSS injection on shared mailboxes. | |
| First Time appeared |
Roundcube
Roundcube webmail |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Roundcube
Roundcube webmail |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-05-25T19:30:38.414Z
Reserved: 2026-05-25T19:30:37.961Z
Link: CVE-2026-48849
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-05-25T21:30:06Z