https://seclists.org/oss-sec/2026/q2/803: CVE-2026-48842+moRoundcube numerous vulnerabilities prior to 1.6.16/1.7.1
Published Jun 3, 2026
·Updated
Affected Software
1 affected component
Roundcube Roundcube<1.6.16, <1.7.1, <=1.5.x
Frequently Asked Questions
1
What is the severity of CVE-2026-48842?
CVE-2026-48842 has a high severity due to its potential for stored XSS and HTML/CSS injection vulnerabilities.
2
How do I fix CVE-2026-48842?
To fix CVE-2026-48842, you should upgrade Roundcube to versions 1.6.16 or 1.7.1.
3
What types of vulnerabilities are associated with CVE-2026-48842?
CVE-2026-48842 is associated with stored XSS and HTML/CSS injection vulnerabilities.
4
Who is affected by CVE-2026-48842?
Anyone using Roundcube versions prior to 1.6.16 and 1.7.1 is affected by CVE-2026-48842.
5
When was CVE-2026-48842 published?
CVE-2026-48842 was published on June 3, 2026.