Groupware
Vendor:
First CVE: Jan 30, 2007 · Active for 19 years
46
Total CVEs
More Total CVEs than 97% of tracked products
3.3
Avg CVEs / Year
Higher CVE frequency than 82% of tracked products
6.0
Avg CVSS
Higher Avg CVSS than 21% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Groupware over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 30, 2007
19 years ago
Most Recent CVE
Dec 2, 2025
234 days ago
CVE Severity & Scoring
Groupware46 CVEs
76%
22%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network24 (52.2%)
Unknown22 (47.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low22 (47.8%)
High2 (4.3%)
Unknown22 (47.8%)
User Interaction
None7 (15.2%)
Unknown22 (47.8%)
Required17 (37.0%)
Privileges Required
Low9 (19.6%)
High0 (0.0%)
None15 (32.6%)
Unknown22 (47.8%)
Top CVEs
Signals from CVEs in this product scope (46 CVEs).
46 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-8518CRITICAL Horde Groupware Webmail Edition 5.2.22 allows injection of arbitrary PHP code via CSV data, leading to remote code execution. | Feb 17, 2020 | 9.8 | 85 | NO | YES |
CVE-2012-0209HIGH Horde 3.3.12, Horde Groupware 1.2.10, and Horde Groupware Webmail Edition 1.2.10, as distributed by FTP between November 2011 and February 2012, contains an externally introduced m | Sep 25, 2012 | 7.5 | 81 | NO | YES |
CVE-2022-30287HIGH Horde Groupware Webmail Edition through 5.2.22 allows a reflection injection attack through which an attacker can instantiate a driver class. This then leads to arbitrary deseriali | Jul 28, 2022 | 8.0 | 65 | NO | NO |
CVE-2017-7413HIGH In Horde_Crypt before 2.7.6, as used in Horde Groupware Webmail Edition through 5.2.17, OS Command Injection can occur if the attacker is an authenticated Horde Webmail user, has P | Apr 4, 2017 | 8.8 | 49 | NO | NO |
CVE-2019-9858HIGH Remote code execution was discovered in Horde Groupware Webmail 5.2.22 and 5.2.17. Horde/Form/Type.php contains a vulnerable class that handles image upload in forms. When the Hord | May 29, 2019 | 8.8 | 41 | NO | YES |
CVE-2020-8866MEDIUM This vulnerability allows remote attackers to create arbitrary files on affected installations of Horde Groupware Webmail Edition 5.2.22. Authentication is required to exploit this | Mar 23, 2020 | 6.5 | 36 | NO | YES |
CVE-2017-15235HIGH The File Manager (gollem) module 3.0.11 in Horde Groupware 5.2.21 allows remote attackers to bypass Horde authentication for file downloads via a crafted fn parameter that correspo | Oct 11, 2017 | 7.5 | 36 | NO | YES |
CVE-2020-8865MEDIUM This vulnerability allows remote attackers to execute local PHP files on affected installations of Horde Groupware Webmail Edition 5.2.22. Authentication is required to exploit thi | Mar 23, 2020 | 6.3 | 34 | NO | YES |
CVE-2013-6364HIGH Horde Groupware Webmail Edition has CSRF and XSS when saving search as a virtual address book | Nov 5, 2019 | 8.8 | 32 | NO | YES |
CVE-2021-26929MEDIUM An XSS issue was discovered in Horde Groupware Webmail Edition through 5.2.22 (where the Horde_Text_Filter library before 2.3.7 is used). The attacker can send a plain text e-mail | Feb 14, 2021 | 6.1 | 30 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (46 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
3 CVEs
6.5% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
13 CVEs
28.3% of CVEs· 90th percentile
Social Chatter
Signals from CVEs in this product scope (46 CVEs).
Media Mentions
Signals from CVEs in this product scope (46 CVEs).
Top CNAs Publishing CVEs For Groupware
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 5.2.7 | 1 | 7.5 | 1.3% | 0 | 0 |
| 5.2.6 | 1 | 7.5 | 1.3% | 0 | 0 |
| 5.2.5 | 1 | 7.5 | 1.3% | 0 | 0 |
| 5.2.4 | 1 | 7.5 | 1.3% | 0 | 0 |
| 5.2.3 | 1 | 7.5 | 1.3% | 0 | 0 |
| 5.2.22 | 6 | 7.1 | 18.1% | 0 | 4 |
| 5.2.21 | 2 | 6.5 | 3.3% | 0 | 1 |
| 5.2.2 | 1 | 7.5 | 1.3% | 0 | 0 |
| 5.2.19 | 2 | 5.4 | 1.4% | 0 | 0 |
| 5.2.17 | 1 | 8.8 | 19.2% | 0 | 1 |
| 5.2.15 | 1 | 6.1 | 1.5% | 0 | 0 |
| 5.2.11 | 1 | 6.1 | 2.1% | 0 | 0 |
| 5.2.1 | 1 | 7.5 | 1.3% | 0 | 0 |
| 5.2.0 | 1 | 7.5 | 1.3% | 0 | 0 |
| 5.1.5 | 1 | 7.5 | 1.3% | 0 | 0 |
| 5.1.4 | 1 | 7.5 | 1.3% | 0 | 0 |
| 5.1.3 | 3 | 5.4 | 1.3% | 0 | 0 |
| 5.1.2 | 5 | 6.0 | 1.4% | 0 | 1 |
| 5.1.1 | 3 | 5.4 | 1.3% | 0 | 0 |
| 5.1.0 | 3 | 5.4 | 1.3% | 0 | 0 |