CVE-2018-14954: Squirrelmail
Medium severity, CVSS 6.1. EPSS: 1.6% chance of exploitation in the next 30 days.
The mail message display page in SquirrelMail through 1.4.22 has XSS via the formaction attribute.
Affected products
- Squirrelmail Squirrelmail: up to and including 1.4.22
Published 2018-08-05. Last modified 2026-06-17.