HighPoC Available
CVE-2026-48842
Roundcube virtuser_query SQL injection
SQLi
Published 25 May 2026
Tracker
PoC, exploit, and active exploitation are separate statuses. If it is not confirmed, the record says Unknown or No PoC.
Filters match the recorded status. Active exploitation is not implied by a proof of concept.
Roundcube virtuser_query SQL injection
SQLi
Published 25 May 2026