VYPR
High severity7.2OSV Advisory· Published Jul 14, 2026· Updated Jul 17, 2026

CVE-2026-54433

CVE-2026-54433

Description

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafted plain-text email message. The attacker-controlled JavaScript executes within the victim's authenticated session simply by opening or previewing the message (zero-click).

Affected products

3
  • Roundcube/WebmailOSV2 versions
    1.6.16, 1.7.1, 1.7.0, …+ 1 more
    • (no CPE)range: 1.6.16, 1.7.1, 1.7.0, …
    • cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:*range: <1.6.17
  • Range: <1.6.17, <1.7.2

Patches

Vulnerability mechanics

References

1

News mentions

2