Products: 37
    Vulnerabilities: 119
    Known Exploited: 0
    5
    Critical Level Threats
    19
    High Level Threats
    89
    Medium Level Threats
    6
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-65053

    Horde IMP before 7.2.0 Stored Cross-Site Scripting via AppleDouble Viewer Part Name

    Last Modified: Aug 26, 2026
    Published: Aug 24, 2026

    CVE-2026-60102

    Horde VFS < 3.0.1 OS Command Injection via Horde_Vfs_Smb Driver

    Last Modified: Jul 10, 2026
    Published: Jul 08, 2026

    CVE-2026-58451

    Horde IMP < 7.0.1 Path Traversal via Compose.php img src

    Last Modified: Jul 14, 2026
    Published: Jul 01, 2026

    CVE-2025-41066

    Disclosure of sensitive information in Horde Groupware

    Last Modified: Dec 03, 2025
    Published: Dec 02, 2025

    CVE-2025-30349

    Horde IMP through 6.2.27, as used with Horde Application Framework through 5.2.23, allows XSS that leads to account takeover via a crafted text/html e-mail message with an onerror attribute (that may use base64-encoded JavaScript code), as exploited in the wild in March 2025.

    Last Modified: Apr 15, 2026
    Published: Mar 21, 2025
    Items Per Page