CVE-2026-48848
Roundcube Webmail 취약점
Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7 has insufficient HTML sanitization that could lead to Cascading Style Sheets (CSS) injection via an SVG document that has an animate element with the attributeName attribute.
- 대응 우선순위
- 점검
- CVSS
- 7.2
- EPSS
- 0.39% 백분위 31.6% · 2026.08.02 기준
- CISA KEV
- 미등록
- 조치 기한
- -
- 공개일
- 2026.05.26