CVE-2018-14953: Squirrelmail

Medium severity, CVSS 6.1. EPSS: 1.4% chance of exploitation in the next 30 days.

The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<math xlink:href=" attack.

Affected products

Published 2018-08-05. Last modified 2026-06-17.