Skip to main content

Vendor archive

horde CVEs

Beta · best-effort

115 CVEs tagged to vendor horde5 Critical, 17 High, 87 Medium, 6 Low, 0 Unrated.

CVE-2025-41066

Published Dec 2, 2025

Horde Groupware v5.2.22 has a user enumeration vulnerability that allows an unauthenticated attacker to determine the existence of valid accounts on the system. To exploit the vul…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-30287

Published Jul 28, 2022

Horde Groupware Webmail Edition through 5.2.22 allows a reflection injection attack through which an attacker can instantiate a driver class. This then leads to arbitrary deserial…

CVSS 8.0 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2021-26929

Published Feb 14, 2021

An XSS issue was discovered in Horde Groupware Webmail Edition through 5.2.22 (where the Horde_Text_Filter library before 2.3.7 is used). The attacker can send a plain text e-mail…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-8034

Published May 18, 2020

Gollem before 3.0.13, as used in Horde Groupware Webmail Edition 5.2.22 and other products, is affected by a reflected Cross-Site Scripting (XSS) vulnerability via the HTTP GET di…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-8035

Published May 18, 2020

The image view functionality in Horde Groupware Webmail Edition before 5.2.22 is affected by a stored Cross-Site Scripting (XSS) vulnerability via an SVG image upload containing a…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-8865

Published Mar 23, 2020

This vulnerability allows remote attackers to execute local PHP files on affected installations of Horde Groupware Webmail Edition 5.2.22. Authentication is required to exploit th…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-12095

Published Oct 24, 2019

Horde Trean, as used in Horde Groupware Webmail Edition through 5.2.22 and other products, allows CSRF, as demonstrated by the treanBookmarkTags parameter to the trean/ URI on a w…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-12094

Published Oct 24, 2019

Horde Groupware Webmail Edition through 5.2.22 allows XSS via an admin/user.php?form=update_f&user_name= or admin/user.php?form=remove_f&user_name= or admin/config/diff.php?app= U…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-9858

Published May 29, 2019

Remote code execution was discovered in Horde Groupware Webmail 5.2.22 and 5.2.17. Horde/Form/Type.php contains a vulnerable class that handles image upload in forms. When the Hor…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-17689

Published May 16, 2018

The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL.

CVSS 5.9 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2017-17688

Published May 16, 2018

The OpenPGP specification allows a Cipher Feedback Mode (CFB) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL. NOTE: third parties report…

CVSS 5.9 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2014-3999

Published Apr 10, 2018

The Horde_Ldap library before 2.0.6 for Horde allows remote attackers to bypass authentication by leveraging knowledge of the LDAP bind user DN.

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2017-16908

Published Nov 20, 2017

In Horde Groupware 5.2.19, there is XSS via the Name field during creation of a new Resource. This can be leveraged for remote code execution after compromising an administrator a…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-16907

Published Nov 20, 2017

In Horde Groupware 5.2.19 and 5.2.21, there is XSS via the Color field in a Create Task List action.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-16906

Published Nov 20, 2017

In Horde Groupware 5.2.19-5.2.22, there is XSS via the URL field in a "Calendar -> New Event" action.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-15235

Published Oct 11, 2017

The File Manager (gollem) module 3.0.11 in Horde Groupware 5.2.21 allows remote attackers to bypass Horde authentication for file downloads via a crafted fn parameter that corresp…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-14650

Published Sep 21, 2017

A Remote Code Execution vulnerability has been found in the Horde_Image library when using the "Im" backend that utilizes ImageMagick's "convert" utility. It's not exploitable thr…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2017-9774

Published Jun 21, 2017

Remote Code Execution was found in Horde_Image 2.x before 2.5.0 via a crafted GET request. Exploitation requires authentication.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-9773

Published Jun 21, 2017

Denial of Service was found in Horde_Image 2.x before 2.5.0 via a crafted URL to the "Null" image driver.

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 115 CVEsPage 1 of 5