CVEs (10)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Cross-site scripting (XSS) vulnerability in Horde_Form in Horde Groupware Webmail Edition before 4.0.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to email verification...Show more |
1Horde 3Dynamic Imp Groupware Webmail EditionImpApr 29, 2026 Jan 24, 2012 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Multiple cross-site scripting (XSS) vulnerabilities in Horde IMP before 5.0.18 and Horde Groupware Webmail Edition before 4.0.6 allow remote attackers to inject arbitrary web script or HTML via the (1) composeCache, (2)...Show more |
1Horde 5Groupware Groupware Webmail EditionKronolith H3+2 moreApr 23, 2026 Sep 13, 2009 N/A· v4 N/A· v3 10.0 HIGH· v2 Horde Kronolith H3 2.1 before 2.1.7 and 2.2 before 2.2-RC2; Nag H3 2.1 before 2.1.4 and 2.2 before 2.2-RC2; Mnemo H3 2.1 before 2.1.2 and H3 2.2 before 2.2-RC2; Groupware 1.0 before 1.0.3 and 1.1 before 1.1-RC2; and Grou...Show more |
1Horde 7Groupware Groupware Webmail EditionHorde+4 moreApr 23, 2026 Sep 13, 2009 N/A· v4 N/A· v3 10.0 HIGH· v2 Unspecified vulnerability in the Horde API in Horde 3.1 before 3.1.6 and 3.2 before 3.2 before 3.2-RC2; Turba H3 2.1 before 2.1.6 and 2.2 before 2.2-RC2; Kronolith H3 2.1 before 2.1.7 and H3 2.2 before 2.2-RC2; Nag H3 2....Show more |
Multiple unspecified vulnerabilities in Horde Groupware Webmail before Edition 1.1.1 (final) have unknown impact and attack vectors related to "unescaped output," possibly cross-site scripting (XSS), in the (1) object br...Show more |
1Horde 3Groupware Groupware Webmail EditionKronolithApr 23, 2026 Jun 19, 2008 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Multiple cross-site scripting (XSS) vulnerabilities in Horde Groupware, Groupware Webmail Edition, and Kronolith allow remote attackers to inject arbitrary web script or HTML via the timestamp parameter to (1) week.php,...Show more |
1Horde 2Groupware Groupware Webmail EditionApr 23, 2026 Apr 27, 2008 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in addevent.php in Horde Kronolith 2.1.7, Groupware Webmail Edition 1.0.6, and Groupware 1.0.5 allows remote attackers to inject arbitrary web script or HTML via the url parameter...Show more |
1Horde 3Groupware Groupware Webmail EditionHordeApr 23, 2026 Mar 11, 2008 N/A· v4 N/A· v3 6.0 MEDIUM· v2 Directory traversal vulnerability in Horde 3.1.6, Groupware before 1.0.5, and Groupware Webmail Edition before 1.0.6, when running with certain configurations, allows remote authenticated users to read and execute arbitr...Show more |
1Horde 3Groupware Groupware Webmail EditionTurba Contact ManagerApr 23, 2026 Feb 19, 2008 N/A· v4 N/A· v3 4.9 MEDIUM· v2 lib/Driver/sql.php in Turba 2 (turba2) Contact Manager H3 2.1.x before 2.1.7 and 2.2.x before 2.2-RC3, as used in products such as Horde Groupware before 1.0.4 and Horde Groupware Webmail Edition before 1.0.5, does not p...Show more |
1Horde 4Framework Groupware Webmail EditionHorde+1 moreApr 23, 2026 Jan 11, 2008 N/A· v4 N/A· v3 5.8 MEDIUM· v2 IMP Webmail Client 4.1.5, Horde Application Framework 3.1.5, and Horde Groupware Webmail Edition 1.0.3 does not validate unspecified HTTP requests, which allows remote attackers to (1) delete arbitrary e-mail messages vi...Show more |