Cross-Site Scripting Vulnerability in Roundcube Webmail Product
CVE-2026-35539
6.1MEDIUM
What is CVE-2026-35539?
A vulnerability in Roundcube Webmail prior to versions 1.5.14 and 1.6.14 allows attackers to execute arbitrary JavaScript via insufficient HTML sanitization of text/html attachments in preview mode. When users preview these attachments, malicious scripts can execute, potentially compromising user data and session integrity.
Affected Version(s)
Webmail 0 < 1.5.14
Webmail 1.6.0 < 1.6.14
