MEDIUM 5.4 NVD

CVE-2026-74999

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the "Add to address book" action was subject to stored XSS.

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the "Add to address book" action was subject to stored XSS.

References

Published: 2026-08-17 · Source: NVD · Feed updated: 2026-08-17
This medium severity vulnerability with a CVSS score of 5.4 was published on 2026-08-17 via NVD.
vulnfeed aggregates 11698 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.