Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Horde

First CVE: Dec 19, 2000Active for: 26 yearsTotal CVEs: 117
37.2
VTI Score
Medium

Horde develops a focused portfolio of groupware and webmail applications centered on its open-source application framework, serving organizations requiring self-hosted collaborative email and calendaring infrastructure. Despite a modestly sized product line, the vendor maintains a prominent presence in the vulnerability landscape, and its disclosures frequently acquire public exploit code. The recurring weakness profile reflects the web-facing nature of the platform: cross-site scripting, cross-site request forgery, and code-injection flaws dominate the exposure, alongside input-validation gaps common to server-side request handling in PHP-based frameworks. Defenders running Horde deployments should monitor framework and application releases closely and isolate these systems from untrusted networks; current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
117
Total CVEs
More Total CVEs than 99% of tracked vendors
0.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
5.6
Avg CVSS Score
Higher Avg CVSS Score than 24% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Horde over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 19, 2000
25 years ago
Most Recent CVE
Jul 1, 2026
23 days ago

Products(36 total)

Top CVEs

Signals from CVEs in this vendor scope (117 CVEs).

117 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-8518CRITICAL
Horde Groupware Webmail Edition 5.2.22 allows injection of arbitrary PHP code via CSV data, leading to remote code execution.
Feb 17, 20209.885NOYES
CVE-2012-0209HIGH
Horde 3.3.12, Horde Groupware 1.2.10, and Horde Groupware Webmail Edition 1.2.10, as distributed by FTP between November 2011 and February 2012, contains an externally introduced m
Sep 25, 20127.581NOYES
CVE-2014-1691HIGH
The framework/Util/lib/Horde/Variables.php script in the Util library in Horde before 5.1.1 allows remote attackers to conduct object injection attacks and execute arbitrary PHP co
Apr 1, 20147.568NOYES
CVE-2022-30287HIGH
Horde Groupware Webmail Edition through 5.2.22 allows a reflection injection attack through which an attacker can instantiate a driver class. This then leads to arbitrary deseriali
Jul 28, 20228.065NONO
CVE-2017-7413HIGH
In Horde_Crypt before 2.7.6, as used in Horde Groupware Webmail Edition through 5.2.17, OS Command Injection can occur if the attacker is an authenticated Horde Webmail user, has P
Apr 4, 20178.849NONO
CVE-2006-1491HIGH
Eval injection vulnerability in Horde Application Framework versions 3.0 before 3.0.10 and 3.1 before 3.1.1 allows remote attackers to execute arbitrary code via the help viewer.
Mar 29, 20067.549NOYES
CVE-2019-9858HIGH
Remote code execution was discovered in Horde Groupware Webmail 5.2.22 and 5.2.17. Horde/Form/Type.php contains a vulnerable class that handles image upload in forms. When the Hord
May 29, 20198.841NOYES
CVE-2025-30349HIGH
Horde IMP through 6.2.27, as used with Horde Application Framework through 5.2.23, allows XSS that leads to account takeover via a crafted text/html e-mail message with an onerror
Mar 21, 20257.239NONO
CVE-2005-3344HIGH
The default installation of Horde 3.0.4 contains an administrative account with a blank password, which allows remote attackers to gain access.
Nov 16, 200510.038NOYES
CVE-2020-8866MEDIUM
This vulnerability allows remote attackers to create arbitrary files on affected installations of Horde Groupware Webmail Edition 5.2.22. Authentication is required to exploit this
Mar 23, 20206.536NOYES
View all 117 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products117 CVEs
75%
19%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network34 (29.1%)
Unknown83 (70.9%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low28 (23.9%)
High6 (5.1%)
Unknown83 (70.9%)
User Interaction
None15 (12.8%)
Unknown83 (70.9%)
Required19 (16.2%)
Privileges Required
Low13 (11.1%)
High0 (0.0%)
None21 (17.9%)
Unknown83 (70.9%)

Exploit Exposure

Signals from CVEs in this vendor scope (117 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
4 CVEs
3.4% of CVEs· 98th percentile
Nuclei
1 CVE
0.9% of CVEs· 95th percentile
ExploitDB
24 CVEs
20.5% of CVEs· 78th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Horde.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Horde — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Horde's Products

View all 6 CNAs →

Top CWEs