All CVEs
Vulnerability intelligence

CVE-2026-48842

CWE-89

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via a preg_replace() backslash escape bypass.

CVSS Score
8.1
High
EPSS — Exploit Probability
0.8%
Riskier than 51% of all CVEs
Exploitation
Not in CISA KEV
No federal exploitation record
Remediation
unknown
Check vendor advisories
NVD entry PoC / advisory

1 article across 1 outlet · first covered May 28, 2026 · latest May 28, 2026

Coverage timeline