VYPR
Medium severity4.7NVD Advisory· Published Jul 14, 2026· Updated Jul 15, 2026

CVE-2026-54432

CVE-2026-54432

Description

Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2 allows Stored Cross-Site Scripting (XSS). The issue occurs because the attachment MIME type is not properly escaped on the attachment-validation warning page.

Affected products

2

Patches

Vulnerability mechanics

References

1

News mentions

3