Retour à la veille
CVE-2026-74999
Score CVSS
5.4
MEDIUM
Description détaillée
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the "Add to address book" action was subject to stored XSS.
Vecteur d'attaque (CVSS)
Vecteur brut :CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Références et Patchs
https://github.com/roundcube/roundcubemail/commit/2d2a9604a820ee279c9ffcfe856b9b93a93995a8https://github.com/roundcube/roundcubemail/commit/32f20c6bfd12dff9cfb6880ae303e740f0804fe8https://github.com/roundcube/roundcubemail/releases/tag/1.6.18https://github.com/roundcube/roundcubemail/releases/tag/1.7.3https://roundcube.net/news/2026/08/09/security-updates-1.6.18-and-1.7.3
Dernières Vulnérabilités
CVE-2026-75060
In JetBrains PyCharm before 2026.2.1 code execution was possible via unauthenticated Jupyter MCP tools
VOIR DÉTAILS
CVE-2026-75059
In JetBrains PyCharm before 2026.2.1 code execution via Quick Documentation was possible
VOIR DÉTAILS
CVE-2026-75058
In JetBrains IntelliJ IDEA before 2026.2.1 xXE was possible in the Eclipse settings importers
VOIR DÉTAILS
