Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13 allows Cascading Style Sheets (CSS) injection, e.g., because comments are mishandled.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 11 Feb 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | roundcubemail: Roundcube Webmail: Cascading Style Sheets (CSS) injection via mishandled comments | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Wed, 11 Feb 2026 05:15:00 +0000
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-02-11T04:44:01.342Z
Reserved: 2026-02-11T04:27:24.001Z
Link: CVE-2026-26079
No data.
Status : Received
Published: 2026-02-11T05:16:28.650
Modified: 2026-02-11T05:16:28.650
Link: CVE-2026-26079
OpenCVE Enrichment
No data.