Horde develops a focused portfolio of groupware and webmail applications centered on its open-source application framework, serving organizations requiring self-hosted collaborative email and calendaring infrastructure. Despite a modestly sized product line, the vendor maintains a prominent presence in the vulnerability landscape, and its disclosures frequently acquire public exploit code. The recurring weakness profile reflects the web-facing nature of the platform: cross-site scripting, cross-site request forgery, and code-injection flaws dominate the exposure, alongside input-validation gaps common to server-side request handling in PHP-based frameworks. Defenders running Horde deployments should monitor framework and application releases closely and isolate these systems from untrusted networks; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Horde over time
Signals from CVEs in this vendor scope (117 CVEs).
117 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-8518CRITICAL Horde Groupware Webmail Edition 5.2.22 allows injection of arbitrary PHP code via CSV data, leading to remote code execution. | Feb 17, 2020 | 9.8 | 85 | NO | YES |
CVE-2012-0209HIGH Horde 3.3.12, Horde Groupware 1.2.10, and Horde Groupware Webmail Edition 1.2.10, as distributed by FTP between November 2011 and February 2012, contains an externally introduced m | Sep 25, 2012 | 7.5 | 81 | NO | YES |
CVE-2014-1691HIGH The framework/Util/lib/Horde/Variables.php script in the Util library in Horde before 5.1.1 allows remote attackers to conduct object injection attacks and execute arbitrary PHP co | Apr 1, 2014 | 7.5 | 68 | NO | YES |
CVE-2022-30287HIGH Horde Groupware Webmail Edition through 5.2.22 allows a reflection injection attack through which an attacker can instantiate a driver class. This then leads to arbitrary deseriali | Jul 28, 2022 | 8.0 | 65 | NO | NO |
CVE-2017-7413HIGH In Horde_Crypt before 2.7.6, as used in Horde Groupware Webmail Edition through 5.2.17, OS Command Injection can occur if the attacker is an authenticated Horde Webmail user, has P | Apr 4, 2017 | 8.8 | 49 | NO | NO |
CVE-2006-1491HIGH Eval injection vulnerability in Horde Application Framework versions 3.0 before 3.0.10 and 3.1 before 3.1.1 allows remote attackers to execute arbitrary code via the help viewer. | Mar 29, 2006 | 7.5 | 49 | NO | YES |
CVE-2019-9858HIGH Remote code execution was discovered in Horde Groupware Webmail 5.2.22 and 5.2.17. Horde/Form/Type.php contains a vulnerable class that handles image upload in forms. When the Hord | May 29, 2019 | 8.8 | 41 | NO | YES |
CVE-2025-30349HIGH Horde IMP through 6.2.27, as used with Horde Application Framework through 5.2.23, allows XSS that leads to account takeover via a crafted text/html e-mail message with an onerror | Mar 21, 2025 | 7.2 | 39 | NO | NO |
CVE-2005-3344HIGH The default installation of Horde 3.0.4 contains an administrative account with a blank password, which allows remote attackers to gain access. | Nov 16, 2005 | 10.0 | 38 | NO | YES |
CVE-2020-8866MEDIUM This vulnerability allows remote attackers to create arbitrary files on affected installations of Horde Groupware Webmail Edition 5.2.22. Authentication is required to exploit this | Mar 23, 2020 | 6.5 | 36 | NO | YES |
Signals from CVEs in this vendor scope (117 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Horde.
Media articles that mention a CVE ID that affects a product developed by Horde — matched by CVE ID, not by vendor name.