Description Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params. Remediation References CVE-2021-44026 Related Vulnerabilities WordPress Plugin Anti-Malware Security and Brute-Force Firewall Cross-Site Scripting (4.15.49) WordPress Plugin Gigya-Social Infrastructure Unspecified Vulnerability (3.0.4) WordPress 5.9.x Multiple Vulnerabilities (5.9 - 5.9.7) WordPress Plugin WP Maintenance Mode Cross-Site Scripting (2.2.3) Ruby Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') Vulnerability (CVE-2017-17742) Severity Critical Classification CVE-2021-44026 CWE-138 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Tags Missing Update Known Vulnerabilities