NULL CATHEDRAL - Vulnerability https://nullcathedral.com/tags/vulnerability/ Generated: 2026-04-10 ================================================================================ 2026-03-18 | Roundcube round two: three more sanitizer bypasses https://nullcathedral.com/posts/2026-03-18-roundcube-round-two-three-more-sanitizer-bypasses/ Three more bypasses in Roundcube's HTML sanitizer: SMIL animation attributes load remote resources, unquoted body backgrounds enable CSS injection, and position:fixed !important enables phishing overlays. 2026-03-16 | Perfex CRM <=3.4.0 allows unauthenticated RCE via insecure deserialization https://nullcathedral.com/posts/2026-03-16-perfex-crm-unauthenticated-rce-insecure-deserialization/ Perfex CRM passed the autologin cookie into unserialize() without validation, giving unauthenticated attackers remote code execution. 2026-02-08 | Roundcube Webmail <1.5.13 / <1.6.13 allows attackers to force remote image loads via SVG feImage https://nullcathedral.com/posts/2026-02-08-roundcube-svg-feimage-remote-image-bypass/ Roundcube's HTML sanitizer doesn't treat SVG feImage href as an image source. Attackers can bypass remote image blocking to track email opens. (CVE-2026-25916)