The mail message display page in SquirrelMail through 1.4.22 has XSS via the formaction attribute.
CVSS Metrics