Garoon

Vendor:

First CVE: Aug 29, 2006 · Active for 19 years

198
Total CVEs
More Total CVEs than 100% of tracked products
12.4
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
5.4
Avg CVSS
Higher Avg CVSS than 16% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Garoon over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 29, 2006
19 years ago
Most Recent CVE
Feb 2, 2026
175 days ago

CVE Severity & Scoring

Garoon198 CVEs
All CVEs352,785 CVEs
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network151 (76.3%)
Unknown47 (23.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low151 (76.3%)
High0 (0.0%)
Unknown47 (23.7%)
User Interaction
None97 (49.0%)
Unknown47 (23.7%)
Required54 (27.3%)
Privileges Required
Low93 (47.0%)
High15 (7.6%)
None43 (21.7%)
Unknown47 (23.7%)

Top CVEs

Signals from CVEs in this product scope (198 CVEs).

198 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Cybozu Garoon 4.2.4 to 4.10.1 allow remote attackers to obtain the users' credential information via the authentication of Cybozu Garoon.
May 17, 20199.829NONO
SQL injection vulnerability in the Cybozu Garoon 3.0.0 to 4.2.2 allows remote authenticated attackers to execute arbitrary SQL commands via "MultiReport" function.
Jun 9, 20178.828NONO
SQL injection vulnerability in Cybozu Garoon before 4.2.2.
Apr 20, 20178.828NONO
SQL injection vulnerability in the Cybozu Garoon 3.5.0 to 4.2.6 allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors.
Apr 16, 20188.827NONO
Operation restriction bypass in multiple applications of Cybozu Garoon 4.0.0 to 5.9.1 allows a remote authenticated attacker to alter the file information and/or delete the files.
Jul 11, 20228.126NONO
Cybozu Garoon 4.0.0 to 4.6.3 allows authenticated attackers to alter the information with privileges invoking the installer via unspecified vectors.
May 17, 20198.726NONO
Directory traversal vulnerability in Cybozu Garoon 3.5.0 to 4.6.3 allows authenticated attackers to read arbitrary files via unspecified vectors.
Nov 15, 20188.126NONO
SQL injection vulnerability in the Notifications application in the Cybozu Garoon 3.5.0 to 4.6.2 allows remote authenticated attackers to execute arbitrary SQL commands via unspeci
Jul 26, 20188.826NONO
Multiple SQL injection vulnerabilities in Cybozu Garoon 2.1.0 for Windows allow remote authenticated users to execute arbitrary SQL commands via the (1) tid parameter in the (a) to
Aug 29, 20066.526NOYES
Improper input verification issue exists in Cybozu Garoon 5.0.0 to 6.0.3, which may lead to unauthorized alteration of portal settings, potentially blocking access to the product.
Feb 2, 20267.525NONO

Exploit Exposure

Signals from CVEs in this product scope (198 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
0.5% of CVEs· 85th percentile

Social Chatter

Signals from CVEs in this product scope (198 CVEs).

Media Mentions

Signals from CVEs in this product scope (198 CVEs).

Top CNAs Publishing CVEs For Garoon

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
5.15.014.30.5%00
5.0.114.91.0%00
5.0.014.91.0%00
4.2.555.20.8%00
4.2.475.20.8%00
4.2.3115.00.9%00
4.2.2205.41.1%00
4.2.1205.41.1%00
4.2.0305.71.2%00
4.0.3325.81.2%00
4.0.2325.81.2%00
4.0.1325.81.2%00
4.0.0275.91.3%00
3.7.5305.81.2%00
3.7.4305.81.2%00
3.7.3295.91.3%00
3.7.2355.81.2%00
3.7.1355.81.2%00
3.7.0365.81.2%00
3.7235.21.3%00