Horde Groupware vulnerabilities
2 known vulnerabilities affecting horde/horde_groupware.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2016-2228MEDIUMCVSS 6.1≤ 5.2.112016-04-13
CVE-2016-2228 [MEDIUM] CWE-79 CVE-2016-2228: Cross-site scripting (XSS) vulnerability in horde/templates/topbar/_menubar.html.php in Horde Groupw
Cross-site scripting (XSS) vulnerability in horde/templates/topbar/_menubar.html.php in Horde Groupware before 5.2.12 and Horde Groupware Webmail Edition before 5.2.12 allows remote attackers to inject arbitrary web script or HTML via the searchfield parameter, as demonstrated by a request to xplorer/gollem/manager.php.
nvd
CVE-2009-3237MEDIUMCVSS 4.3v1.1.1v1.1.2+7 more2009-09-17
CVE-2009-3237 [MEDIUM] CWE-79 CVE-2009-3237: Multiple cross-site scripting (XSS) vulnerabilities in Horde Application Framework 3.2 before 3.2.5
Multiple cross-site scripting (XSS) vulnerabilities in Horde Application Framework 3.2 before 3.2.5 and 3.3 before 3.3.5; Groupware 1.1 before 1.1.6 and 1.2 before 1.2.4; and Groupware Webmail Edition 1.1 before 1.1.6 and 1.2 before 1.2.4; allow remote attackers to inject arbitrary web script or HTML via the (1) crafted number preferences that are not p
nvd