Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-74998

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, responses from the CSS (Cascading Style Sheets) proxy were not validated, which may result in information disclosure or XSS (cross-site scripting) via MIME sniffing.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 18.8%
CVSS Severity
CVSS v3 Score 7.2
Products affected by CVE-2026-74998


Contact Us

Shodan ® - All rights reserved