CVEs (46)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Horde 3Groupware Groupware Webmail EditionKronolithApr 23, 2026 Jun 19, 2008 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Multiple cross-site scripting (XSS) vulnerabilities in Horde Groupware, Groupware Webmail Edition, and Kronolith allow remote attackers to inject arbitrary web script or HTML via the timestamp parameter to (1) week.php,...Show more |
1Horde 2Groupware Groupware Webmail EditionApr 23, 2026 Apr 27, 2008 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in addevent.php in Horde Kronolith 2.1.7, Groupware Webmail Edition 1.0.6, and Groupware 1.0.5 allows remote attackers to inject arbitrary web script or HTML via the url parameter...Show more |
1Horde 3Groupware Groupware Webmail EditionHordeApr 23, 2026 Mar 11, 2008 N/A· v4 N/A· v3 6.0 MEDIUM· v2 Directory traversal vulnerability in Horde 3.1.6, Groupware before 1.0.5, and Groupware Webmail Edition before 1.0.6, when running with certain configurations, allows remote authenticated users to read and execute arbitr...Show more |
1Horde 3Groupware Groupware Webmail EditionTurba Contact ManagerApr 23, 2026 Feb 19, 2008 N/A· v4 N/A· v3 4.9 MEDIUM· v2 lib/Driver/sql.php in Turba 2 (turba2) Contact Manager H3 2.1.x before 2.1.7 and 2.2.x before 2.2-RC3, as used in products such as Horde Groupware before 1.0.4 and Horde Groupware Webmail Edition before 1.0.5, does not p...Show more |
Multiple cross-site scripting (XSS) vulnerabilities in Horde Groupware Webmail 1.0 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors in (1) imp/search.php and (2) ingo/rule.p...Show more |
Unspecified vulnerability in the calendar component in Horde Groupware Webmail Edition before 1.0, and Groupware before 1.0, allows remote attackers to include certain files via unspecified vectors. NOTE: some of these...Show more |