Description
Roundcube before 1.4.13 and 1.5.x before 1.5.2 allows XSS via an HTML e-mail message with crafted Cascading Style Sheets (CSS) token sequences.
Remediation
References
Related Vulnerabilities
WordPress Plugin Media from FTP Cross-Site Scripting (9.89)
Dolibarr Improper Handling of Case Sensitivity Vulnerability (CVE-2026-89012)
WordPress Plugin Yoast SEO Security Bypass (1.4.6)
MySQL Use of Externally-Controlled Format String Vulnerability (CVE-2008-3963)
WordPress Plugin Advanced Access Manager Unspecified Vulnerability (5.9.8.1)