Horde Vulnerabilities and Affected Products
Vulnerabilities associated with imp.
Products
Clear product- imp3 vulnerabilities
- Groupware Webmail Edition2 vulnerabilities
- dynamic_imp1 vulnerability
- Groupware1 vulnerability
- Horde IMP1 vulnerability
- Vfs1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-58451HIGH | Horde IMP < 7.0.1 Path Traversal via Compose.php img srcHorde IMP before 7.0.1 contains a path traversal vulnerability in lib/Compose.php that allows authenticated attackers to read arbitrary files from the server filesystem by embedding traversal sequences after a CKEditor path prefix in img src URLs. Attackers can bypass the stripos() prefix validation by appending sequences such as traversal segments after the matching prefix, causing file_get_contents() to read sensitive files whose contents are then exfiltrated as MIME parts in outgoing email; u… CWE-22Jul 1, 2026 | CVSS7.1v4.0 | EPSS0.409% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-30349HIGH | horde imp Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')Horde IMP through 6.2.27, as used with Horde Application Framework through 5.2.23, allows XSS that leads to account takeover via a crafted text/html e-mail message with an onerror attribute (that may use base64-encoded JavaScript code), as exploited in the wild in March 2025. CWE-79Mar 21, 2025 | CVSS7.2v3.1 | EPSS30.2% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2002-2024MEDIUM | Horde IMP 2.2.7 allows remote attackers to obtain the full web root pathname via an HTTP request for (1) poppassd.php3, (2) login.php3?reason=chpass2, (3) spelling.php3, and (4) ldap.search.php3?ldap_serv=nonsense which leaks the information in error messages. CWE-219Jul 14, 2005 | CVSS5.3v3.1 | EPSS1.92% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |