← Back

Office

office

Vendor: Cybozu • 71 CVEs

CVEs (71)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cybozu
1Office
May 13, 2026
Apr 17, 2017
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Cybozu Office 9.0.0 to 10.4.0 allows remote authenticated attackers to execute unintended operations via the Project function.
1Cybozu
1Office
May 13, 2026
Apr 17, 2017
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Cybozu Office 9.0.0 to 10.4.0 allows remote authenticated attackers to bypass access restrictions to view the names of unauthorized projects via a breadcrumb trail.
1Cybozu
1Office
May 13, 2026
Apr 17, 2017
N/A· v4
6.5 MEDIUM· v3
6.8 MEDIUM· v2
Cybozu Office 9.0.0 through 10.4.0 allows remote attackers to cause a denial of service.
1Cybozu
1Office
May 13, 2026
Apr 17, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting vulnerability in Cybozu Office 9.0.0 to 10.4.0 allows remote authenticated attackers to inject arbitrary web script or HTML via the Schedule function.
1Cybozu
1Office
May 13, 2026
Apr 17, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Cybozu Office 9.0.0 to 10.4.0 allow remote attackers to obtain session information via a page where CGI environment variables are displayed.
1Cybozu
1Office
May 13, 2026
Apr 17, 2017
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Email header injection vulnerability in Cybozu Office 9.0.0 to 10.4.0 allows remote attackers to inject arbitrary email headers to send unintended emails via specially crafted requests.
1Cybozu
1Office
May 13, 2026
Apr 17, 2017
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Cybozu Office 9.0.0 to 10.4.0 allows remote authenticated attackers to bypass access restriction to view unauthorized project information via the Project function.
1Cybozu
1Office
May 13, 2026
Apr 17, 2017
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting vulnerability in Cybozu Office 9.0.0 to 10.4.0 allows attackers with administrator rights to inject arbitrary web script or HTML via the Project function.
1Cybozu
1Office
May 13, 2026
Apr 17, 2017
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting vulnerability in Cybozu Office 9.0.0 to 10.4.0 allows attackers with administrator rights to inject arbitrary web script or HTML via the Customapp function.
1Cybozu
1Office
May 6, 2026
Feb 17, 2016
N/A· v4
6.5 MEDIUM· v3
6.8 MEDIUM· v2
customapp in Cybozu Office 9.9.0 through 10.3.0 allows remote authenticated users to cause a denial of service via unspecified vectors, a different vulnerability than CVE-2015-8489.
1Cybozu
1Office
May 6, 2026
Feb 17, 2016
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
Cybozu Office 9.9.0 through 10.3.0 allows remote authenticated users to bypass intended access restrictions, and read or write to plan data, via unspecified vectors, a different vulnerability than CVE-2015-8484, CVE-2015...Show more
Cybozu Office 9.9.0 through 10.3.0 allows remote authenticated users to bypass intended access restrictions, and read or write to plan data, via unspecified vectors, a different vulnerability than CVE-2015-8484, CVE-2015-8485, and CVE-2015-8486.Show less
1Cybozu
1Office
May 6, 2026
Feb 17, 2016
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Multiple cross-site request forgery (CSRF) vulnerabilities in Cybozu Office 9.9.0 through 10.3.0 allow remote attackers to hijack the authentication of arbitrary users.
1Cybozu
1Office
May 6, 2026
Feb 17, 2016
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in Cybozu Office 9.0.0 through 10.3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-7795, CVE-201...Show more
Cross-site scripting (XSS) vulnerability in Cybozu Office 9.0.0 through 10.3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-7795, CVE-2015-7796, CVE-2015-7797, CVE-2015-7798, and CVE-2016-1149.Show less
1Cybozu
1Office
May 6, 2026
Feb 17, 2016
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in Cybozu Office 9.0.0 through 10.3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-7795, CVE-201...Show more
Cross-site scripting (XSS) vulnerability in Cybozu Office 9.0.0 through 10.3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-7795, CVE-2015-7796, CVE-2015-7797, CVE-2015-7798, and CVE-2016-1150.Show less
1Cybozu
1Office
May 6, 2026
Feb 17, 2016
N/A· v4
6.5 MEDIUM· v3
6.8 MEDIUM· v2
customapp in Cybozu Office 9.9.0 through 10.3.0 allows remote authenticated users to cause a denial of service (excessive database locking) via a crafted CSV file, a different vulnerability than CVE-2016-1153.
1Cybozu
1Office
May 6, 2026
Feb 17, 2016
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Cybozu Office 10.3.0 allows remote attackers to read image files via a crafted e-mail message, a different vulnerability than CVE-2015-8487.
1Cybozu
1Office
May 6, 2026
Feb 17, 2016
N/A· v4
4.3 MEDIUM· v3
2.6 LOW· v2
Cybozu Office 9.0.0 through 10.3 allows remote attackers to discover CSRF tokens via unspecified vectors, a different vulnerability than CVE-2015-8488.
1Cybozu
1Office
May 6, 2026
Feb 17, 2016
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
Cybozu Office 9.9.0 through 10.3.0 allows remote authenticated users to bypass intended access restrictions and read arbitrary report titles via unspecified vectors, a different vulnerability than CVE-2015-8484, CVE-2015...Show more
Cybozu Office 9.9.0 through 10.3.0 allows remote authenticated users to bypass intended access restrictions and read arbitrary report titles via unspecified vectors, a different vulnerability than CVE-2015-8484, CVE-2015-8485, and CVE-2016-1152.Show less
1Cybozu
1Office
May 6, 2026
Feb 17, 2016
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
Cybozu Office 9.9.0 through 10.3.0 allows remote authenticated users to bypass intended access restrictions and read arbitrary posting titles via unspecified vectors, a different vulnerability than CVE-2015-8484, CVE-201...Show more
Cybozu Office 9.9.0 through 10.3.0 allows remote authenticated users to bypass intended access restrictions and read arbitrary posting titles via unspecified vectors, a different vulnerability than CVE-2015-8484, CVE-2015-8486, and CVE-2016-1152.Show less
1Cybozu
1Office
May 6, 2026
Feb 17, 2016
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
Cybozu Office 9.9.0 through 10.3.0 allows remote authenticated users to bypass intended calendar-viewing restrictions via unspecified vectors, a different vulnerability than CVE-2015-8485, CVE-2015-8486, and CVE-2016-115...Show more
Cybozu Office 9.9.0 through 10.3.0 allows remote authenticated users to bypass intended calendar-viewing restrictions via unspecified vectors, a different vulnerability than CVE-2015-8485, CVE-2015-8486, and CVE-2016-1152.Show less