CVE-2026-48849
MEDIUMRoundcube Webmail - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Title source: ruleExploitation Summary
EIP tracks 2 public exploits for CVE-2026-48849. PoCs published by AnandJogawade.
AI-analyzed exploit summary The repository contains a technical writeup and proof-of-concept images demonstrating a stored XSS vulnerability in Roundcube Webmail (CVE-2026-48849). The README and images provide details on how the vulnerability can be exploited, but no functional exploit code is included.
Description
In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, an unsanitized subject field in the draft restored value could lead to stored XSS/HTML/CSS injection on shared mailboxes.
Exploits (2)
The repository contains a technical writeup and proof-of-concept images demonstrating a stored XSS vulnerability in Roundcube Webmail (CVE-2026-48849). The README and images provide details on how the vulnerability can be exploited, but no functional exploit code is included.
The repository contains a technical writeup and proof-of-concept screenshots demonstrating a stored XSS vulnerability in Roundcube Webmail (CVE-2026-48849). The README and images detail the exploit steps but do not include executable code.
References (5)
Scores
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N