Vulnerability threat dossier

CVE-2024-37383

roundcubewebmail

Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.

VTP deterministic threat44.7of 100 · CVSS excluded

VTP analyst assessment

Known-exploited Roundcube SVG XSS

AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateREVIEWED
AI priorityNONE
AI confidence90%
Public exploitation · VTP factKEV

Assessment

CVE-2024-37383 allows cross-site scripting through SVG animate attributes in vulnerable Roundcube Webmail releases. CISA KEV lists the flaw as known exploited globally. Successful XSS can execute attacker-controlled script in a user's webmail session.

Why it matters

  • Webmail sessions can contain sensitive messages and user actions.
  • Exploitation requires a victim to interact with malicious content, according to the CVSS user-interaction prerequisite.

Evidence

1 record references and 0 source references passed trusted post-response validation. The current deterministic record contains 0 independent evidence groups.

Uncertainties

No relevant current campaign details or exploit mechanism beyond the vulnerability description are available.

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

Next watchpoint

If you use Roundcube Webmail before 1.5.7 or 1.6.x before 1.6.7, upgrade to a fixed release.

AI baseline history (2)
  1. BASELINE ASSESSED
    Known-exploited Roundcube SVG XSSgpt-5.6-terra · low
  2. BASELINE ASSESSED
    Roundcube Webmail SVG XSSgpt-5.6-sol · high
Technical severityMEDIUMCVSS 6.1 · technical context
Public exploitationKEVGlobal public evidence
Exploit maturityNONE KNOWNReliability not implied
EPSS0.7399th percentile · prediction
Evidence confidence0%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
Availability: SENSOR_ONLINE_NO_MATCHING_ACTIVITY · Evidence: UNKNOWN
01

VTP deterministic assessment

Why this matters

  1. 01

    CISA KEV lists this vulnerability as known to be exploited globally.

  2. 02

    EPSS is 0.73; this is predictive context, not exploitation evidence.

  3. 03

    First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

02

Material change ledger

What changed

KEV ADDEDCISA KEV entry added
03

Claim provenance

Evidence and source independence

1publications detected
1underlying evidence chains

0 primary sources · 0 dependent secondary reports · 1 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

04

Event history

Threat timeline

  1. 00:0024 Oct
    KEV ADDED

    CISA KEV entry added

    CISA lists global known exploitation. This is not a VTP sensor observation.

05

Original publications

Source record

Roundcube Webmail Vulnerability in Attackers’ Crosshairs

Tracked as CVE-2026-48842, the exploited bug is an SQL injection that can be exploited without authentication. The post Roundcube Webmail Vulnerability in Attackers’ Crosshairs appeared first on SecurityWeek .

CVE-2024-37383CVE-2025-49113CVE-2025-68461CVE-2026-48842
Separate evidence group
Original
06

Technical vulnerability data

Context, not threat proof

VTP threat score44.7vtp-threat-v1-public
Public exploitation30 / 30
EPSS prediction14.66 / 20
Exploit availability0 / 15
Source independence0 / 15
Intelligence recency0 / 10
Threat acceleration0 / 10
CVSS technical severityExcluded
CVSS
6.1 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CWE
CWE-79
CPE records
2
Deterministic history records
20
Primary technical reference
07

Raw observations

First-party sensor records

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.