CVE-2016-7968: Kde Kmail

Medium severity, CVSS 6.5. EPSS: 1.2% chance of exploitation in the next 30 days.

KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled. HTML Mail contents were not sanitized for JavaScript and included code was executed.

Affected products

  • Kde Kmail: up to and including 5.3.0

Published 2016-12-23. Last modified 2026-06-17.