← Back

Garoon

garoon

Vendor: Cybozu • 198 CVEs

CVEs (198)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cybozu
1Garoon
Jun 17, 2026
Aug 18, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting vulnerability in Bulletin of Cybozu Garoon 4.6.0 to 5.0.2 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.
1Cybozu
1Garoon
Jun 17, 2026
Aug 18, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Operational restrictions bypass vulnerability in Scheduler and MultiReport of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to delete the data of Scheduler and MultiReport without the appropriate pr...Show more
Operational restrictions bypass vulnerability in Scheduler and MultiReport of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to delete the data of Scheduler and MultiReport without the appropriate privilege.Show less
1Cybozu
1Garoon
Jun 17, 2026
Aug 18, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting vulnerability in Full Text Search of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.
1Cybozu
1Garoon
Jun 17, 2026
Aug 18, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting vulnerability in Message of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote attacker to inject an arbitrary script via unspecified vectors.
1Cybozu
1Garoon
Jun 17, 2026
Aug 18, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting vulnerability in Bulletin of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote attacker to inject an arbitrary script via unspecified vectors.
1Cybozu
1Garoon
Jun 17, 2026
Aug 18, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Improper input validation vulnerability in Attaching Files of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote attacker to alter the data of Attaching Files.
1Cybozu
1Garoon
Jun 17, 2026
Aug 18, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Operational restrictions bypass vulnerability in Portal of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to obtain the data of Portal without the appropriate privilege.
1Cybozu
1Garoon
Jun 17, 2026
Aug 18, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Improper input validation vulnerability in E-mail of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated to alter the data of E-mail without the appropriate privilege.
1Cybozu
1Garoon
Jun 17, 2026
Aug 18, 2021
N/A· v4
2.7 LOW· v3
3.5 LOW· v2
Improper input validation vulnerability in E-mail of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote attacker with an administrative privilege to alter the data of E-mail without the appropriate privilege.
1Cybozu
1Garoon
Jun 17, 2026
Aug 18, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Improper input validation vulnerability in User Profile of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to alter the data of User Profile without the appropriate privilege.
1Cybozu
1Garoon
Jun 17, 2026
Aug 18, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Operational restrictions bypass vulnerability in Bulletin of Cybozu Garoon 4.6.0 to 5.0.2 allows a remote authenticated attacker to alter the data of Portal without the appropriate privilege.
1Cybozu
1Garoon
Jun 17, 2026
Aug 18, 2021
N/A· v4
8.0 HIGH· v3
6.0 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in Message of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to hijack the authentication of administrators and perform an arbitrary operation via unsp...Show more
Cross-site request forgery (CSRF) vulnerability in Message of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to hijack the authentication of administrators and perform an arbitrary operation via unspecified vectors.Show less
1Cybozu
1Garoon
Jun 17, 2026
Aug 18, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Operational restrictions bypass vulnerability in E-mail of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to alter the data of Portal without the appropriate privilege.
1Cybozu
1Garoon
Jun 17, 2026
Aug 18, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Viewing restrictions bypass vulnerability in Address of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to obtain the data of Address without the viewing privilege.
1Cybozu
1Garoon
Jun 17, 2026
Aug 18, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Viewing restrictions bypass vulnerability in Portal of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to obtain the data of Portal without the viewing privilege.
1Cybozu
1Garoon
Jun 17, 2026
Aug 18, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Improper input validation vulnerability in Workflow of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to alter the data of Workflow without the appropriate privilege.
1Cybozu
1Garoon
Jun 17, 2026
Aug 18, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting vulnerability in Scheduler of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.
1Cybozu
1Garoon
Jun 17, 2026
Nov 6, 2020
N/A· v4
6.5 MEDIUM· v3
5.5 MEDIUM· v2
Improper input validation vulnerability in Cybozu Garoon 5.0.0 to 5.0.2 allows a remote authenticated attacker to delete some data of the bulletin board via unspecified vector.
1Cybozu
1Garoon
Jun 17, 2026
Jun 30, 2020
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
Path traversal vulnerability in Cybozu Garoon 5.0.0 to 5.0.1 allows attacker with administrator rights to obtain unintended information via unspecified vectors.
1Cybozu
1Garoon
Jun 17, 2026
Jun 30, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Cybozu Garoon 4.0.0 to 5.0.1 allow remote authenticated attackers to obtain unintended information via unspecified vectors.