The Email Viewer in RainLoop through 1.6.0 allows XSS via a crafted email message.
- https://blog.sonarsource.com/rainloop-emails-at-risk-due-to-code-flaw/
No PoCs found on GitHub currently.