ZeroHour

CVE-2026-74999

CVSS 3.1
5.4 medium
EPSS
<1%p12
Published
()
Modified
Description

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the "Add to address book" action was subject to stored XSS.

Vendors
roundcube
Products
webmail
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.