Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.
https://www.darkreading.com/application-security/poc-code-escalates-roundcube-vuln-threat
https://thehackernews.com/2025/06/critical-10-year-old-roundcube-webmail.html
https://thehackernews.com/2024/10/hackers-exploit-roundcube-webmail-xss.html
https://github.com/amirzargham/CVE-2024-37383-exploit
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-37383
https://github.com/roundcube/roundcubemail/releases/tag/1.6.7
https://github.com/roundcube/roundcubemail/releases/tag/1.5.7
https://github.com/roundcube/roundcubemail/commit/43aaaa528646877789ec028d87924ba1accf5242