Medium severity6.1CISA KEVNVD Advisory· Published Jun 7, 2024· Updated Jun 17, 2026
CVE-2024-37383
CVE-2024-37383
Description
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
5- github.com/roundcube/roundcubemail/commit/43aaaa528646877789ec028d87924ba1accf5242nvdPatch
- lists.debian.org/debian-lts-announce/2024/06/msg00008.htmlnvdMailing ListThird Party Advisory
- github.com/roundcube/roundcubemail/releases/tag/1.5.7nvdRelease Notes
- github.com/roundcube/roundcubemail/releases/tag/1.6.7nvdRelease Notes
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
1- Russian Threat Groups Use RDP, VPN, Supply Chain Attacks, and Social Engineering for Initial AccessCyber Security News · May 22, 2026