Vulnerability Details CVE-2026-74999
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the "Add to address book" action was subject to stored XSS.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 11.8%
CVSS Severity
CVSS v3 Score 5.4
Products affected by CVE-2026-74999
-
cpe:2.3:a:roundcube:webmail:*
-
cpe:2.3:a:roundcube:webmail:1.6.0
-
cpe:2.3:a:roundcube:webmail:1.6.1
-
cpe:2.3:a:roundcube:webmail:1.6.10
-
cpe:2.3:a:roundcube:webmail:1.6.11
-
cpe:2.3:a:roundcube:webmail:1.6.12
-
cpe:2.3:a:roundcube:webmail:1.6.13
-
cpe:2.3:a:roundcube:webmail:1.6.14
-
cpe:2.3:a:roundcube:webmail:1.6.2
-
cpe:2.3:a:roundcube:webmail:1.6.3
-
cpe:2.3:a:roundcube:webmail:1.6.4
-
cpe:2.3:a:roundcube:webmail:1.6.5
-
cpe:2.3:a:roundcube:webmail:1.6.6
-
cpe:2.3:a:roundcube:webmail:1.6.7
-
cpe:2.3:a:roundcube:webmail:1.6.8
-
cpe:2.3:a:roundcube:webmail:1.6.9