All CVEs
Vulnerability intelligence

CVE-2026-48842

Roundcube Webmail CWE-89

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via a preg_replace() backslash escape bypass.

CVSS Score
8.1
High
EPSS — Exploit Probability
0.8%
Riskier than 53% of all CVEs · checked 2026-09-07
Exploitation
Not in CISA KEV
KEV does not include every exploited vulnerability
Remediation
unknown
Check vendor advisories
NVD entry PoC / advisory

1 article across 1 outlet · first covered May 28, 2026 · latest May 28, 2026

Coverage timeline

Related CVEs — Roundcube