Imp
Vendor:
First CVE: Dec 19, 2000 · Active for 25 years
23
Total CVEs
More Total CVEs than 95% of tracked products
1.5
Avg CVEs / Year
Higher CVE frequency than 59% of tracked products
5.2
Avg CVSS
Higher Avg CVSS than 9% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Imp over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 19, 2000
25 years ago
Most Recent CVE
Jul 1, 2026
23 days ago
CVE Severity & Scoring
Imp23 CVEs
9%
74%
17%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network3 (13.0%)
Unknown20 (87.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (13.0%)
High0 (0.0%)
Unknown20 (87.0%)
User Interaction
None3 (13.0%)
Unknown20 (87.0%)
Required0 (0.0%)
Privileges Required
Low1 (4.3%)
High0 (0.0%)
None2 (8.7%)
Unknown20 (87.0%)
Top CVEs
Signals from CVEs in this product scope (23 CVEs).
23 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-30349HIGH Horde IMP through 6.2.27, as used with Horde Application Framework through 5.2.23, allows XSS that leads to account takeover via a crafted text/html e-mail message with an onerror | Mar 21, 2025 | 7.2 | 39 | NO | NO |
CVE-2003-0025HIGH Multiple SQL injection vulnerabilities in IMP 2.2.8 and earlier allow remote attackers to perform unauthorized database activities and possibly gain privileges via certain database | Jan 17, 2003 | 7.5 | 34 | NO | NO |
CVE-2026-58451MEDIUM Horde IMP before 7.0.1 contains a path traversal vulnerability in lib/Compose.php that allows authenticated attackers to read arbitrary files from the server filesystem by embeddin | Jul 1, 2026 | 6.5 | 31 | NO | NO |
CVE-2007-1474MEDIUM Argument injection vulnerability in the cleanup cron script in Horde Project Horde and IMP before Horde Application Framework 3.1.4 allows local users to delete arbitrary files and | Mar 16, 2007 | 6.8 | 28 | NO | YES |
CVE-2010-3695MEDIUM Cross-site scripting (XSS) vulnerability in fetchmailprefs.php in Horde IMP before 4.3.8, and Horde Groupware Webmail Edition before 1.2.7, allows remote attackers to inject arbitr | Mar 31, 2011 | 4.3 | 27 | NO | YES |
CVE-2002-2024MEDIUM Horde IMP 2.2.7 allows remote attackers to obtain the full web root pathname via an HTTP request for (1) poppassd.php3, (2) login.php3?reason=chpass2, (3) spelling.php3, and (4) ld | Dec 31, 2002 | 5.3 | 22 | NO | NO |
CVE-2007-1515MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Horde IMP H3 4.1.3, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via (1) the email Sub | Mar 20, 2007 | 4.3 | 21 | NO | YES |
CVE-2005-4080MEDIUM Horde IMP 4.0.4 and earlier does not sanitize strings containing UTF16 null characters, which allows remote attackers to conduct cross-site scripting (XSS) attacks via UTF16 encode | Dec 8, 2005 | 4.3 | 21 | NO | YES |
CVE-2002-0181HIGH Cross-site scripting vulnerability in status.php3 for IMP 2.2.8 and HORDE 1.2.7 allows remote attackers to execute arbitrary web script and steal cookies of other IMP/HORDE users v | Apr 22, 2002 | 7.5 | 20 | NO | NO |
CVE-2001-1257HIGH Cross-site scripting vulnerability in Horde Internet Messaging Program (IMP) before 2.2.6 and 1.2.6 allows remote attackers to execute arbitrary Javascript embedded in an email. | Jul 21, 2001 | 7.5 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (23 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
17.4% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (23 CVEs).
Media Mentions
Signals from CVEs in this product scope (23 CVEs).
Top CNAs Publishing CVEs For Imp
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 5.0.9 | 2 | 4.3 | 1.8% | 0 | 0 |
| 5.0.8 | 2 | 4.3 | 1.8% | 0 | 0 |
| 5.0.7 | 2 | 4.3 | 1.8% | 0 | 0 |
| 5.0.6 | 2 | 4.3 | 1.8% | 0 | 0 |
| 5.0.5 | 2 | 4.3 | 1.8% | 0 | 0 |
| 5.0.4-git | 1 | 4.3 | 2.4% | 0 | 0 |
| 5.0.4 | 2 | 4.3 | 1.8% | 0 | 0 |
| 5.0.3 | 2 | 4.3 | 2.1% | 0 | 0 |
| 5.0.22 | 1 | 4.3 | 1.8% | 0 | 0 |
| 5.0.21 | 1 | 4.3 | 1.8% | 0 | 0 |
| 5.0.20 | 2 | 4.3 | 1.8% | 0 | 0 |
| 5.0.2 | 2 | 4.3 | 2.1% | 0 | 0 |
| 5.0.19 | 2 | 4.3 | 1.8% | 0 | 0 |
| 5.0.18 | 2 | 4.3 | 1.8% | 0 | 0 |
| 5.0.17 | 2 | 4.3 | 1.8% | 0 | 0 |
| 5.0.16 | 2 | 4.3 | 1.8% | 0 | 0 |
| 5.0.15 | 2 | 4.3 | 1.8% | 0 | 0 |
| 5.0.14 | 2 | 4.3 | 1.8% | 0 | 0 |
| 5.0.13 | 2 | 4.3 | 1.8% | 0 | 0 |
| 5.0.12 | 2 | 4.3 | 1.8% | 0 | 0 |