Imp

Vendor:

First CVE: Dec 19, 2000 · Active for 25 years

23
Total CVEs
More Total CVEs than 95% of tracked products
1.5
Avg CVEs / Year
Higher CVE frequency than 59% of tracked products
5.2
Avg CVSS
Higher Avg CVSS than 9% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Imp over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 19, 2000
25 years ago
Most Recent CVE
Jul 1, 2026
23 days ago

CVE Severity & Scoring

Imp23 CVEs
All CVEs352,294 CVEs
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network3 (13.0%)
Unknown20 (87.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (13.0%)
High0 (0.0%)
Unknown20 (87.0%)
User Interaction
None3 (13.0%)
Unknown20 (87.0%)
Required0 (0.0%)
Privileges Required
Low1 (4.3%)
High0 (0.0%)
None2 (8.7%)
Unknown20 (87.0%)

Top CVEs

Signals from CVEs in this product scope (23 CVEs).

23 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Horde IMP through 6.2.27, as used with Horde Application Framework through 5.2.23, allows XSS that leads to account takeover via a crafted text/html e-mail message with an onerror
Mar 21, 20257.239NONO
Multiple SQL injection vulnerabilities in IMP 2.2.8 and earlier allow remote attackers to perform unauthorized database activities and possibly gain privileges via certain database
Jan 17, 20037.534NONO
Horde IMP before 7.0.1 contains a path traversal vulnerability in lib/Compose.php that allows authenticated attackers to read arbitrary files from the server filesystem by embeddin
Jul 1, 20266.531NONO
Argument injection vulnerability in the cleanup cron script in Horde Project Horde and IMP before Horde Application Framework 3.1.4 allows local users to delete arbitrary files and
Mar 16, 20076.828NOYES
Cross-site scripting (XSS) vulnerability in fetchmailprefs.php in Horde IMP before 4.3.8, and Horde Groupware Webmail Edition before 1.2.7, allows remote attackers to inject arbitr
Mar 31, 20114.327NOYES
Horde IMP 2.2.7 allows remote attackers to obtain the full web root pathname via an HTTP request for (1) poppassd.php3, (2) login.php3?reason=chpass2, (3) spelling.php3, and (4) ld
Dec 31, 20025.322NONO
Multiple cross-site scripting (XSS) vulnerabilities in Horde IMP H3 4.1.3, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via (1) the email Sub
Mar 20, 20074.321NOYES
Horde IMP 4.0.4 and earlier does not sanitize strings containing UTF16 null characters, which allows remote attackers to conduct cross-site scripting (XSS) attacks via UTF16 encode
Dec 8, 20054.321NOYES
Cross-site scripting vulnerability in status.php3 for IMP 2.2.8 and HORDE 1.2.7 allows remote attackers to execute arbitrary web script and steal cookies of other IMP/HORDE users v
Apr 22, 20027.520NONO
Cross-site scripting vulnerability in Horde Internet Messaging Program (IMP) before 2.2.6 and 1.2.6 allows remote attackers to execute arbitrary Javascript embedded in an email.
Jul 21, 20017.520NONO

Exploit Exposure

Signals from CVEs in this product scope (23 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
17.4% of CVEs· 89th percentile

Social Chatter

Signals from CVEs in this product scope (23 CVEs).

Media Mentions

Signals from CVEs in this product scope (23 CVEs).

Top CNAs Publishing CVEs For Imp

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
5.0.924.31.8%00
5.0.824.31.8%00
5.0.724.31.8%00
5.0.624.31.8%00
5.0.524.31.8%00
5.0.4-git14.32.4%00
5.0.424.31.8%00
5.0.324.32.1%00
5.0.2214.31.8%00
5.0.2114.31.8%00
5.0.2024.31.8%00
5.0.224.32.1%00
5.0.1924.31.8%00
5.0.1824.31.8%00
5.0.1724.31.8%00
5.0.1624.31.8%00
5.0.1524.31.8%00
5.0.1424.31.8%00
5.0.1324.31.8%00
5.0.1224.31.8%00