CVE-2018-14950: Squirrelmail

Medium severity, CVSS 6.1. EPSS: 1.4% chance of exploitation in the next 30 days.

The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<svg><a xlink:href=" attack.

Affected products

Published 2018-08-05. Last modified 2026-06-17.