Vulnerability index

Browse CVEs

45 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Groupware MEDIUM 5.3
CVE-2025-41066

Horde Groupware v5.2.22 has a user enumeration vulnerability that allows an unauthenticated attacker to determine the existence of valid accounts on …

Mitigation only
Fix from $1,600 2025-12-02
Gollem MEDIUM 6.1
CVE-2020-8034

Gollem before 3.0.13, as used in Horde Groupware Webmail Edition 5.2.22 and other products, is affected by a reflected Cross-Site Scripting (XSS) vul…

Fix: 3.0.13+
Fix from $1,600 2020-05-18
Groupware MEDIUM 6.1
CVE-2020-8035

The image view functionality in Horde Groupware Webmail Edition before 5.2.22 is affected by a stored Cross-Site Scripting (XSS) vulnerability via an…

Fix: 5.2.22+
Fix from $1,600 2020-05-18
Groupware HIGH 8.8
CVE-2019-12095

Horde Trean, as used in Horde Groupware Webmail Edition through 5.2.22 and other products, allows CSRF, as demonstrated by the treanBookmarkTags para…

Fix: after 5.2.22
Fix from $1,950 2019-10-24
Groupware MEDIUM 6.1
CVE-2019-12094

Horde Groupware Webmail Edition through 5.2.22 allows XSS via an admin/user.php?form=update_f&user_name= or admin/user.php?form=remove_f&user_name= o…

Fix: after 5.2.22
Fix from $1,600 2019-10-24
Horde Ldap HIGH 8.1
CVE-2014-3999

The Horde_Ldap library before 2.0.6 for Horde allows remote attackers to bypass authentication by leveraging knowledge of the LDAP bind user DN.

Fix: 2.0.6+
Fix from $1,950 2018-04-10
Groupware MEDIUM 5.4
CVE-2017-16906

In Horde Groupware 5.2.19-5.2.22, there is XSS via the URL field in a "Calendar -> New Event" action.

Fix: after 5.2.22
Fix from $1,600 2017-11-20
Groupware MEDIUM 5.4
CVE-2017-16907

In Horde Groupware 5.2.19 and 5.2.21, there is XSS via the Color field in a Create Task List action.

Patch available
Fix from $1,600 2017-11-20
Groupware MEDIUM 5.4
CVE-2017-16908

In Horde Groupware 5.2.19, there is XSS via the Name field during creation of a new Resource. This can be leveraged for remote code execution after c…

Patch available
Fix from $1,600 2017-11-20
Groupware HIGH 7.5
CVE-2017-15235EPSS 6%

The File Manager (gollem) module 3.0.11 in Horde Groupware 5.2.21 allows remote attackers to bypass Horde authentication for file downloads via a cra…

No fix yet
Fix from $1,950 2017-10-11
Horde Image Api HIGH 8.1
CVE-2017-14650

A Remote Code Execution vulnerability has been found in the Horde_Image library when using the "Im" backend that utilizes ImageMagick's "convert" uti…

Patch available
Fix from $1,950 2017-09-21
Horde Image Api HIGH 8.8
CVE-2017-9774

Remote Code Execution was found in Horde_Image 2.x before 2.5.0 via a crafted GET request. Exploitation requires authentication.

Mitigation only
Fix from $1,950 2017-06-21
Horde Image MEDIUM 5.7
CVE-2017-9773

Denial of Service was found in Horde_Image 2.x before 2.5.0 via a crafted URL to the "Null" image driver.

No fix yet
Fix from $1,600 2017-06-21
Groupware HIGH 8.8
CVE-2017-7413EPSS 40%

In Horde_Crypt before 2.7.6, as used in Horde Groupware Webmail Edition through 5.2.17, OS Command Injection can occur if the attacker is an authenti…

Fix: after 5.2.17
Fix from $1,950 2017-04-04
Groupware HIGH 7.5
CVE-2017-7414

In Horde_Crypt before 2.7.6, as used in Horde Groupware Webmail Edition 5.x through 5.2.17, OS Command Injection can occur if the user has PGP featur…

Mitigation only
Fix from $1,950 2017-04-04
Groupware MEDIUM 6.1
CVE-2016-5303

Cross-site scripting (XSS) vulnerability in the Horde Text Filter API in Horde Groupware and Horde Groupware Webmail Edition before 5.2.16 allows rem…

Patch available
Fix from $1,600 2016-12-20
Horde Application Framework HIGH 7.5
CVE-2014-1691EPSS 43%

The framework/Util/lib/Horde/Variables.php script in the Util library in Horde before 5.1.1 allows remote attackers to conduct object injection attac…

Fix: after 5.1.0
Fix from $1,950 2014-04-01
Groupware HIGH 7.5
CVE-2012-0209EPSS 72%

Horde 3.3.12, Horde Groupware 1.2.10, and Horde Groupware Webmail Edition 1.2.10, as distributed by FTP between November 2011 and February 2012, cont…

Patch available
Fix from $1,950 2012-09-25
Horde Application Framework MEDIUM 6.8
CVE-2010-3694

Cross-site request forgery (CSRF) vulnerability in the Horde Application Framework before 3.3.9 allows remote attackers to hijack the authentication …

Fix: after 3.3.8
Fix from $1,600 2010-11-09
Horde MEDIUM 5.0
CVE-2010-1638

The IMP plugin in Horde allows remote attackers to bypass firewall restrictions and use Horde as a proxy to scan internal networks via a crafted requ…

Mitigation only
Fix from $1,600 2010-06-22
Imp MEDIUM 5.0
CVE-2010-0463

Horde IMP 4.3.6 and earlier does not request that the web browser avoid DNS prefetching of domain names contained in e-mail messages, which makes it …

Fix: after 4.3.6
Fix from $1,600 2010-01-29
Groupware HIGH 10.0
CVE-2008-7218

Unspecified vulnerability in the Horde API in Horde 3.1 before 3.1.6 and 3.2 before 3.2 before 3.2-RC2; Turba H3 2.1 before 2.1.6 and 2.2 before 2.2-…

Patch available
Fix from $1,950 2009-09-13
Groupware HIGH 10.0
CVE-2008-7219

Horde Kronolith H3 2.1 before 2.1.7 and 2.2 before 2.2-RC2; Nag H3 2.1 before 2.1.4 and 2.2 before 2.2-RC2; Mnemo H3 2.1 before 2.1.2 and H3 2.2 befo…

Patch available
Fix from $1,950 2009-09-13
Groupware Webmail Edition HIGH 9.0
CVE-2008-3650

Multiple unspecified vulnerabilities in Horde Groupware Webmail before Edition 1.1.1 (final) have unknown impact and attack vectors related to "unesc…

Patch available
Fix from $1,950 2008-08-13
Groupware MEDIUM 6.0
CVE-2008-1284

Directory traversal vulnerability in Horde 3.1.6, Groupware before 1.0.5, and Groupware Webmail Edition before 1.0.6, when running with certain confi…

Fix: after 1.0.5
Fix from $1,600 2008-03-11
Framework MEDIUM 5.8
CVE-2007-6018

IMP Webmail Client 4.1.5, Horde Application Framework 3.1.5, and Horde Groupware Webmail Edition 1.0.3 does not validate unspecified HTTP requests, w…

Patch available
Fix from $1,600 2008-01-11
Groupware MEDIUM 5.4
CVE-2007-1679

Multiple cross-site scripting (XSS) vulnerabilities in Horde Groupware Webmail 1.0 allow remote authenticated users to inject arbitrary web script or…

Mitigation only
Fix from $1,600 2007-03-26
Horde Application Framework MEDIUM 6.8
CVE-2007-1474

Argument injection vulnerability in the cleanup cron script in Horde Project Horde and IMP before Horde Application Framework 3.1.4 allows local user…

Patch available
Fix from $1,600 2007-03-16
Groupware MEDIUM 5.1
CVE-2007-0579

Unspecified vulnerability in the calendar component in Horde Groupware Webmail Edition before 1.0, and Groupware before 1.0, allows remote attackers …

Patch available
Fix from $1,600 2007-01-30
Kronolith HIGH 7.5
CVE-2006-6175

Directory traversal vulnerability in lib/FBView.php in Horde Kronolith H3 before 2.0.7 and 2.1.x before 2.1.4 allows remote attackers to include arbi…

Patch available
Fix from $1,950 2006-11-30