Vulnerabilities in Horde
7 resultsVexday analysis
A Horde apresenta um perfil de risco baixo com apenas 4 CVEs registrados na base e nenhum sob ataque ativo ou com severidade crítica. A fraqueza dominante identificada é exposição de informação (CWE-200), porém sem registros de publicação nos últimos 90 dias, indicando que as vulnerabilidades conhecidas não estão em exploração ativa ou recente.
CVE-2025-30349HIGHHorde IMP through 6.2.27, as used with Horde Application Framework through 5.2.23, allows XSS that leads to account takeover via a crafted tEPSS 31.3%CVE-2020-8866MEDIUMThis vulnerability allows remote attackers to create arbitrary files on affected installations of Horde Groupware Webmail Edition 5.2.22. AuEPSS 9.6%CVE-2020-8865MEDIUMThis vulnerability allows remote attackers to execute local PHP files on affected installations of Horde Groupware Webmail Edition 5.2.22. AEPSS 6.8%CVE-2026-60102HIGHHorde VFS < 3.0.1 OS Command Injection via Horde_Vfs_Smb DriverEPSS 3.3%CVE-2026-58451HIGHHorde IMP < 7.0.1 Path Traversal via Compose.php img srcEPSS 0.6%CVE-2026-65053MEDIUMHorde IMP before 7.2.0 Stored Cross-Site Scripting via AppleDouble Viewer Part NameEPSS 0.2%CVE-2025-41066MEDIUMDisclosure of sensitive information in Horde GroupwareEPSS 0.2%