Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4693-1 | roundcube security update |
Debian DSA |
DSA-6391-1 | roundcube security update |
Mon, 20 Jul 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Stored XSS via Unescaped MIME Type on Attachment Validation in Roundcube Webmail |
Thu, 16 Jul 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Stored XSS via Unescaped MIME Type on Attachment Validation in Roundcube Webmail |
Tue, 14 Jul 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2 allows Stored Cross-Site Scripting (XSS). The issue occurs because the attachment MIME type is not properly escaped on the attachment-validation warning page. | |
| First Time appeared |
Roundcube
Roundcube webmail |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Roundcube
Roundcube webmail |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-07-15T15:13:14.654Z
Reserved: 2026-06-15T13:27:41.810Z
Link: CVE-2026-54432
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-20T22:30:19Z
Debian DLA
Debian DSA