Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.
https://thehackernews.com/2024/10/hackers-exploit-roundcube-webmail-xss.html
https://lists.debian.org/debian-lts-announce/2024/06/msg00008.html
https://github.com/roundcube/roundcubemail/releases/tag/1.6.7
https://github.com/roundcube/roundcubemail/releases/tag/1.5.7
https://github.com/roundcube/roundcubemail/commit/43aaaa528646877789ec028d87924ba1accf5242