PT-2026-54448 · Mozilla · Thunderbird

·

CVE-2026-57963

·

Published

2026-07-01

·

Updated

2026-07-19

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Thunderbird versions prior to 140.12.1 Thunderbird versions prior to 152.0.1
Description An attacker can inject arbitrary styled content, phishing links, and CSS to manipulate the chat UI by sending HTML chat messages via Matrix or XMPP.
Recommendations Update to version 140.12.1. Update to version 152.0.1.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-57963
OESA-2026-2936
OESA-2026-3093
OPENSUSE-SU-2026:11164-1

Affected Products

Thunderbird