CVE-2024-37383π₯ Known Exploited (CISA KEV)MEDIUM6.1CVSS Severity ScoreEPSS Score0.0000%EPSS Percentile0.00thPublished2024-06-07Last Modified2026-06-17Data SourcesNVDCISA KEVVulnerability DescriptionRoundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.Affected Platforms (CPE)π¦RoundcubeWebmail< 1.5.7>= 1.6.0 and < 1.6.7π»DebianDebian Linux= 10.0References & Advisoriesπ https://github.com/roundcube/roundcubemail/commit/43aaaa528646877789ec028d87924ba1accf5242π https://github.com/roundcube/roundcubemail/releases/tag/1.5.7π https://github.com/roundcube/roundcubemail/releases/tag/1.6.7π https://lists.debian.org/debian-lts-announce/2024/06/msg00008.htmlπ https://github.com/roundcube/roundcubemail/commit/43aaaa528646877789ec028d87924ba1accf5242π https://github.com/roundcube/roundcubemail/releases/tag/1.5.7π https://github.com/roundcube/roundcubemail/releases/tag/1.6.7π https://lists.debian.org/debian-lts-announce/2024/06/msg00008.html