Skip to main content

Vendor archive

cybozu CVEs

Beta · best-effort

330 CVEs tagged to vendor cybozu8 Critical, 37 High, 269 Medium, 16 Low, 0 Unrated.

CVE-2026-22888

Published Feb 2, 2026

Improper input verification issue exists in Cybozu Garoon 5.0.0 to 6.0.3, which may lead to unauthorized alteration of portal settings, potentially blocking access to the product.

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-22881

Published Feb 2, 2026

Cross-site scripting vulnerability exists in Message function of Cybozu Garoon 5.15.0 to 6.0.3, which may allow an attacker to reset arbitrary users’ passwords.

CVSS 6.8 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-20711

Published Feb 2, 2026

Cross-site scripting vulnerability exists in E-mail function of Cybozu Garoon 5.0.0 to 6.0.3, which may allow an attacker to reset arbitrary users’ passwords.

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2024-39817

Published Aug 6, 2024

Insertion of sensitive information into sent data issue exists in Cybozu Office 10.0.0 to 10.8.6, which may allow a user who can login to the product to view data that the user do…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-39457

Published Jul 19, 2024

Cybozu Garoon 6.0.0 to 6.0.1 contains a cross-site scripting vulnerability in PDF preview. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in u…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-31402

Published Jun 11, 2024

Incorrect authorization vulnerability in Cybozu Garoon 5.0.0 to 5.15.2 allows a remote authenticated attacker to delete the data of Shared To-Dos.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-31399

Published Jun 11, 2024

Excessive platform resource consumption within a loop issue exists in Cybozu Garoon 5.0.0 to 5.15.2. If this vulnerability is exploited, processing a crafted mail may cause a deni…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-31398

Published Jun 11, 2024

Insertion of sensitive information into sent data issue exists in Cybozu Garoon 5.0.0 to 5.15.2. If this vulnerability is exploited, a user who can log in to the product may obtai…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-31397

Published Jun 11, 2024

Improper handling of extra values issue exists in Cybozu Garoon 5.0.0 to 5.15.2. If this vulnerability is exploited, a user who can log in to the product with the administrative p…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-31404

Published Jun 11, 2024

Insertion of sensitive information into sent data issue exists in Cybozu Garoon 5.5.0 to 6.0.0, which may allow a user who can log in to the product to view the data of Scheduler.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-31403

Published Jun 11, 2024

Incorrect authorization vulnerability in Cybozu Garoon 5.0.0 to 6.0.0 allows a remote authenticated attacker to alter and/or obtain the data of Memo.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-31401

Published Jun 11, 2024

Cross-site scripting vulnerability in Cybozu Garoon 5.0.0 to 5.15.2 allows a remote authenticated attacker with an administrative privilege to inject an arbitrary script on the we…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-31400

Published Jun 11, 2024

Insertion of sensitive information into sent data issue exists in Cybozu Garoon 5.0.0 to 5.15.0. If this vulnerability is exploited, unintended data may be left in forwarded mail.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-23304

Published Feb 6, 2024

Cybozu KUNAI for Android 3.0.20 to 3.0.21 allows a remote unauthenticated attacker to cause a denial-of-service (DoS) condition by performing certain operations.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-46278

Published Nov 1, 2023

Uncontrolled resource consumption vulnerability in Cybozu Remote Service 4.1.0 to 4.1.1 allows a remote authenticated attacker to consume huge storage space or cause significantly…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-26838

Published Aug 3, 2023

Path traversal vulnerability in Importing Mobile Device Data of Cybozu Remote Service 3.1.2 allows a remote authenticated attacker to cause a denial-of-service (DoS) condition.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-27384

Published May 23, 2023

Operation restriction bypass vulnerability in MultiReport of Cybozu Garoon 5.15.0 allows a remote authenticated attacker to alter the data of MultiReport.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-27304

Published May 23, 2023

Operation restriction bypass vulnerability in Message and Bulletin of Cybozu Garoon 4.6.0 to 5.9.2 allows a remote authenticated attacker to alter the data of Message and/or Bulle…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-26595

Published May 23, 2023

Denial-of-service (DoS) vulnerability in Message of Cybozu Garoon 4.10.0 to 5.9.2 allows a remote authenticated attacker to cause a denial of service condition.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-44608

Published Dec 7, 2022

Uncontrolled resource consumption vulnerability in Cybozu Remote Service 4.0.0 to 4.0.3 allows a remote authenticated attacker to consume huge storage space, which may result in a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-33311

Published Aug 18, 2022

Browse restriction bypass vulnerability in Address Book of Cybozu Office 10.0.0 to 10.8.5 allows a remote authenticated attacker to obtain the data of Address Book via unspecified…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-33151

Published Aug 18, 2022

Cross-site scripting vulnerability in the specific parameters of Cybozu Office 10.0.0 to 10.8.5 allows remote attackers to inject an arbitrary script via unspecified vectors.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-32583

Published Aug 18, 2022

Operation restriction bypass vulnerability in Scheduler of Cybozu Office 10.0.0 to 10.8.5 allows a remote authenticated attacker to alter the data of Scheduler via unspecified vec…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-32544

Published Aug 18, 2022

Operation restriction bypass vulnerability in Project of Cybozu Office 10.0.0 to 10.8.5 allows a remote authenticated attacker to alter the data of Project via unspecified vectors.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-32453

Published Aug 18, 2022

HTTP header injection vulnerability in Cybozu Office 10.0.0 to 10.8.5 may allow a remote attacker to obtain and/or alter the data of the product via unspecified vectors.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 330 CVEsPage 1 of 14