Horde / Groupware
46 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-41066 | Disclosure of sensitive information in Horde Groupware | MEDIUM | 6.9 | Dec 2, 2025 |
| CVE-2022-30287 | Horde Groupware Webmail Edition through 5.2.22 allows a reflection injection attack through which an attacker can instantiate a driver class. This then leads t… | HIGH | 8.0 | Jul 28, 2022 |
| CVE-2021-26929 | An XSS issue was discovered in Horde Groupware Webmail Edition through 5.2.22 (where the Horde_Text_Filter library before 2.3.7 is used). The attacker can send… | MEDIUM | 6.1 | Feb 14, 2021 |
| CVE-2020-8034 | Gollem before 3.0.13, as used in Horde Groupware Webmail Edition 5.2.22 and other products, is affected by a reflected Cross-Site Scripting (XSS) vulnerability… | MEDIUM | 6.1 | May 18, 2020 |
| CVE-2020-8035 | The image view functionality in Horde Groupware Webmail Edition before 5.2.22 is affected by a stored Cross-Site Scripting (XSS) vulnerability via an SVG image… | MEDIUM | 6.1 | May 18, 2020 |
| CVE-2020-8866 | This vulnerability allows remote attackers to create arbitrary files on affected installations of Horde Groupware Webmail Edition 5.2.22. Authentication is req… | MEDIUM | 6.5 | Mar 23, 2020 |
| CVE-2020-8865 | This vulnerability allows remote attackers to execute local PHP files on affected installations of Horde Groupware Webmail Edition 5.2.22. Authentication is re… | MEDIUM | 6.3 | Mar 23, 2020 |
| CVE-2020-8518 | Horde Groupware Webmail Edition 5.2.22 allows injection of arbitrary PHP code via CSV data, leading to remote code execution. | CRITICAL | 9.8 | Feb 17, 2020 |
| CVE-2013-6275 | Multiple CSRF issues in Horde Groupware Webmail Edition 5.1.2 and earlier in basic.php. | MEDIUM | 6.5 | Nov 5, 2019 |
| CVE-2013-6365 | Horde Groupware Web mail 5.1.2 has CSRF with requests to change permissions | MEDIUM | 5.3 | Nov 5, 2019 |
| CVE-2013-6364 | Horde Groupware Webmail Edition has CSRF and XSS when saving search as a virtual address book | HIGH | 8.8 | Nov 5, 2019 |
| CVE-2019-12095 | Horde Trean, as used in Horde Groupware Webmail Edition through 5.2.22 and other products, allows CSRF, as demonstrated by the treanBookmarkTags parameter to t… | HIGH | 8.8 | Oct 24, 2019 |
| CVE-2019-12094 | Horde Groupware Webmail Edition through 5.2.22 allows XSS via an admin/user.php?form=update_f&user_name= or admin/user.php?form=remove_f&user_name= or admin/co… | MEDIUM | 6.1 | Oct 24, 2019 |
| CVE-2019-9858 | Remote code execution was discovered in Horde Groupware Webmail 5.2.22 and 5.2.17. Horde/Form/Type.php contains a vulnerable class that handles image upload in… | HIGH | 8.8 | May 29, 2019 |
| CVE-2017-16908 | In Horde Groupware 5.2.19, there is XSS via the Name field during creation of a new Resource. This can be leveraged for remote code execution after compromisin… | MEDIUM | 5.4 | Nov 20, 2017 |
| CVE-2017-16907 | In Horde Groupware 5.2.19 and 5.2.21, there is XSS via the Color field in a Create Task List action. | MEDIUM | 5.4 | Nov 20, 2017 |
| CVE-2017-16906 | In Horde Groupware 5.2.19-5.2.22, there is XSS via the URL field in a "Calendar -> New Event" action. | MEDIUM | 5.4 | Nov 20, 2017 |
| CVE-2017-15235 | The File Manager (gollem) module 3.0.11 in Horde Groupware 5.2.21 allows remote attackers to bypass Horde authentication for file downloads via a crafted fn pa… | HIGH | 7.5 | Oct 11, 2017 |
| CVE-2017-7414 | In Horde_Crypt before 2.7.6, as used in Horde Groupware Webmail Edition 5.x through 5.2.17, OS Command Injection can occur if the user has PGP features enabled… | HIGH | 7.5 | Apr 4, 2017 |
| CVE-2017-7413 | In Horde_Crypt before 2.7.6, as used in Horde Groupware Webmail Edition through 5.2.17, OS Command Injection can occur if the attacker is an authenticated Hord… | HIGH | 8.8 | Apr 4, 2017 |
| CVE-2016-5303 | Cross-site scripting (XSS) vulnerability in the Horde Text Filter API in Horde Groupware and Horde Groupware Webmail Edition before 5.2.16 allows remote attack… | MEDIUM | 6.1 | Dec 20, 2016 |
| CVE-2016-2228 | Cross-site scripting (XSS) vulnerability in horde/templates/topbar/_menubar.html.php in Horde Groupware before 5.2.12 and Horde Groupware Webmail Edition befor… | MEDIUM | 6.1 | Apr 13, 2016 |
| CVE-2015-8807 | Cross-site scripting (XSS) vulnerability in the _renderVarInput_number function in horde/framework/Core/lib/Horde/Core/Ui/VarRenderer/Html.php in Horde Groupwa… | MEDIUM | 6.1 | Apr 13, 2016 |
| CVE-2015-7984 | Multiple cross-site request forgery (CSRF) vulnerabilities in Horde before 5.2.8, Horde Groupware before 5.2.11, and Horde Groupware Webmail Edition before 5.2… | MEDIUM | 6.8 | Nov 19, 2015 |
| CVE-2014-4946 | Multiple cross-site scripting (XSS) vulnerabilities in Horde Internet Mail Program (IMP) before 6.1.8, as used in Horde Groupware Webmail Edition before 5.1.5,… | MEDIUM | 4.3 | Jul 14, 2014 |
Showing 1 to 25 of 46 CVEs