TROYANOSYVIRUS
Back to CVEs

CVE-2026-26079

MEDIUM
4.7

Description

Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13 allows Cascading Style Sheets (CSS) injection, e.g., because comments are mishandled.

This product uses data from the NVD API but is not endorsed or certified by the NVD.