Groupware

Vendor:

First CVE: Jan 30, 2007 · Active for 19 years

46
Total CVEs
More Total CVEs than 97% of tracked products
3.3
Avg CVEs / Year
Higher CVE frequency than 82% of tracked products
6.0
Avg CVSS
Higher Avg CVSS than 21% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Groupware over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 30, 2007
19 years ago
Most Recent CVE
Dec 2, 2025
234 days ago

CVE Severity & Scoring

Groupware46 CVEs
All CVEs352,294 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network24 (52.2%)
Unknown22 (47.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low22 (47.8%)
High2 (4.3%)
Unknown22 (47.8%)
User Interaction
None7 (15.2%)
Unknown22 (47.8%)
Required17 (37.0%)
Privileges Required
Low9 (19.6%)
High0 (0.0%)
None15 (32.6%)
Unknown22 (47.8%)

Top CVEs

Signals from CVEs in this product scope (46 CVEs).

46 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Horde Groupware Webmail Edition 5.2.22 allows injection of arbitrary PHP code via CSV data, leading to remote code execution.
Feb 17, 20209.885NOYES
Horde 3.3.12, Horde Groupware 1.2.10, and Horde Groupware Webmail Edition 1.2.10, as distributed by FTP between November 2011 and February 2012, contains an externally introduced m
Sep 25, 20127.581NOYES
Horde Groupware Webmail Edition through 5.2.22 allows a reflection injection attack through which an attacker can instantiate a driver class. This then leads to arbitrary deseriali
Jul 28, 20228.065NONO
In Horde_Crypt before 2.7.6, as used in Horde Groupware Webmail Edition through 5.2.17, OS Command Injection can occur if the attacker is an authenticated Horde Webmail user, has P
Apr 4, 20178.849NONO
Remote code execution was discovered in Horde Groupware Webmail 5.2.22 and 5.2.17. Horde/Form/Type.php contains a vulnerable class that handles image upload in forms. When the Hord
May 29, 20198.841NOYES
This vulnerability allows remote attackers to create arbitrary files on affected installations of Horde Groupware Webmail Edition 5.2.22. Authentication is required to exploit this
Mar 23, 20206.536NOYES
The File Manager (gollem) module 3.0.11 in Horde Groupware 5.2.21 allows remote attackers to bypass Horde authentication for file downloads via a crafted fn parameter that correspo
Oct 11, 20177.536NOYES
This vulnerability allows remote attackers to execute local PHP files on affected installations of Horde Groupware Webmail Edition 5.2.22. Authentication is required to exploit thi
Mar 23, 20206.334NOYES
Horde Groupware Webmail Edition has CSRF and XSS when saving search as a virtual address book
Nov 5, 20198.832NOYES
An XSS issue was discovered in Horde Groupware Webmail Edition through 5.2.22 (where the Horde_Text_Filter library before 2.3.7 is used). The attacker can send a plain text e-mail
Feb 14, 20216.130NOYES

Exploit Exposure

Signals from CVEs in this product scope (46 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
3 CVEs
6.5% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
13 CVEs
28.3% of CVEs· 90th percentile

Social Chatter

Signals from CVEs in this product scope (46 CVEs).

Media Mentions

Signals from CVEs in this product scope (46 CVEs).

Top CNAs Publishing CVEs For Groupware

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
5.2.717.51.3%00
5.2.617.51.3%00
5.2.517.51.3%00
5.2.417.51.3%00
5.2.317.51.3%00
5.2.2267.118.1%04
5.2.2126.53.3%01
5.2.217.51.3%00
5.2.1925.41.4%00
5.2.1718.819.2%01
5.2.1516.11.5%00
5.2.1116.12.1%00
5.2.117.51.3%00
5.2.017.51.3%00
5.1.517.51.3%00
5.1.417.51.3%00
5.1.335.41.3%00
5.1.256.01.4%01
5.1.135.41.3%00
5.1.035.41.3%00