CVE-2024-37383🔥 Known Exploited (CISA KEV)MEDIUM6.1CVSS Severity ScoreEPSS Score0.0000%EPSS Percentile0.00thPublished2024-06-07Last Modified2026-06-17Data SourcesNVDCISA KEVVulnerability DescriptionRoundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.Affected Platforms (CPE)📦RoundcubeWebmail< 1.5.7>= 1.6.0 and < 1.6.7💻DebianDebian Linux= 10.0References & Advisories🔗 https://github.com/roundcube/roundcubemail/commit/43aaaa528646877789ec028d87924ba1accf5242🔗 https://github.com/roundcube/roundcubemail/releases/tag/1.5.7🔗 https://github.com/roundcube/roundcubemail/releases/tag/1.6.7🔗 https://lists.debian.org/debian-lts-announce/2024/06/msg00008.html🔗 https://github.com/roundcube/roundcubemail/commit/43aaaa528646877789ec028d87924ba1accf5242🔗 https://github.com/roundcube/roundcubemail/releases/tag/1.5.7🔗 https://github.com/roundcube/roundcubemail/releases/tag/1.6.7🔗 https://lists.debian.org/debian-lts-announce/2024/06/msg00008.html