Garoon
Vendor:
First CVE: Aug 29, 2006 · Active for 19 years
198
Total CVEs
More Total CVEs than 100% of tracked products
12.4
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
5.4
Avg CVSS
Higher Avg CVSS than 16% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Garoon over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 29, 2006
19 years ago
Most Recent CVE
Feb 2, 2026
175 days ago
CVE Severity & Scoring
Garoon198 CVEs
80%
13%
All CVEs352,785 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network151 (76.3%)
Unknown47 (23.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low151 (76.3%)
High0 (0.0%)
Unknown47 (23.7%)
User Interaction
None97 (49.0%)
Unknown47 (23.7%)
Required54 (27.3%)
Privileges Required
Low93 (47.0%)
High15 (7.6%)
None43 (21.7%)
Unknown47 (23.7%)
Top CVEs
Signals from CVEs in this product scope (198 CVEs).
198 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-5945CRITICAL Cybozu Garoon 4.2.4 to 4.10.1 allow remote attackers to obtain the users' credential information via the authentication of Cybozu Garoon. | May 17, 2019 | 9.8 | 29 | NO | NO |
CVE-2016-7803HIGH SQL injection vulnerability in the Cybozu Garoon 3.0.0 to 4.2.2 allows remote authenticated attackers to execute arbitrary SQL commands via "MultiReport" function. | Jun 9, 2017 | 8.8 | 28 | NO | NO |
CVE-2016-1218HIGH SQL injection vulnerability in Cybozu Garoon before 4.2.2. | Apr 20, 2017 | 8.8 | 28 | NO | NO |
CVE-2018-0530HIGH SQL injection vulnerability in the Cybozu Garoon 3.5.0 to 4.2.6 allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors. | Apr 16, 2018 | 8.8 | 27 | NO | NO |
CVE-2022-30602HIGH Operation restriction bypass in multiple applications of Cybozu Garoon 4.0.0 to 5.9.1 allows a remote authenticated attacker to alter the file information and/or delete the files. | Jul 11, 2022 | 8.1 | 26 | NO | NO |
CVE-2019-5931HIGH Cybozu Garoon 4.0.0 to 4.6.3 allows authenticated attackers to alter the information with privileges invoking the installer via unspecified vectors. | May 17, 2019 | 8.7 | 26 | NO | NO |
CVE-2018-0673HIGH Directory traversal vulnerability in Cybozu Garoon 3.5.0 to 4.6.3 allows authenticated attackers to read arbitrary files via unspecified vectors. | Nov 15, 2018 | 8.1 | 26 | NO | NO |
CVE-2018-0607HIGH SQL injection vulnerability in the Notifications application in the Cybozu Garoon 3.5.0 to 4.6.2 allows remote authenticated attackers to execute arbitrary SQL commands via unspeci | Jul 26, 2018 | 8.8 | 26 | NO | NO |
CVE-2006-4444MEDIUM Multiple SQL injection vulnerabilities in Cybozu Garoon 2.1.0 for Windows allow remote authenticated users to execute arbitrary SQL commands via the (1) tid parameter in the (a) to | Aug 29, 2006 | 6.5 | 26 | NO | YES |
CVE-2026-22888HIGH Improper input verification issue exists in Cybozu Garoon 5.0.0 to 6.0.3, which may lead to unauthorized alteration of portal settings, potentially blocking access to the product. | Feb 2, 2026 | 7.5 | 25 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (198 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
0.5% of CVEs· 85th percentile
Social Chatter
Signals from CVEs in this product scope (198 CVEs).
Media Mentions
Signals from CVEs in this product scope (198 CVEs).
Top CNAs Publishing CVEs For Garoon
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 5.15.0 | 1 | 4.3 | 0.5% | 0 | 0 |
| 5.0.1 | 1 | 4.9 | 1.0% | 0 | 0 |
| 5.0.0 | 1 | 4.9 | 1.0% | 0 | 0 |
| 4.2.5 | 5 | 5.2 | 0.8% | 0 | 0 |
| 4.2.4 | 7 | 5.2 | 0.8% | 0 | 0 |
| 4.2.3 | 11 | 5.0 | 0.9% | 0 | 0 |
| 4.2.2 | 20 | 5.4 | 1.1% | 0 | 0 |
| 4.2.1 | 20 | 5.4 | 1.1% | 0 | 0 |
| 4.2.0 | 30 | 5.7 | 1.2% | 0 | 0 |
| 4.0.3 | 32 | 5.8 | 1.2% | 0 | 0 |
| 4.0.2 | 32 | 5.8 | 1.2% | 0 | 0 |
| 4.0.1 | 32 | 5.8 | 1.2% | 0 | 0 |
| 4.0.0 | 27 | 5.9 | 1.3% | 0 | 0 |
| 3.7.5 | 30 | 5.8 | 1.2% | 0 | 0 |
| 3.7.4 | 30 | 5.8 | 1.2% | 0 | 0 |
| 3.7.3 | 29 | 5.9 | 1.3% | 0 | 0 |
| 3.7.2 | 35 | 5.8 | 1.2% | 0 | 0 |
| 3.7.1 | 35 | 5.8 | 1.2% | 0 | 0 |
| 3.7.0 | 36 | 5.8 | 1.2% | 0 | 0 |
| 3.7 | 23 | 5.2 | 1.3% | 0 | 0 |