VYPR

Garoon

by Cybozu

CVEs (201)

  • CVE-2019-5945CriMay 17, 2019
    risk 0.64cvss 9.8epss 0.02

    Cybozu Garoon 4.2.4 to 4.10.1 allow remote attackers to obtain the users' credential information via the authentication of Cybozu Garoon.

  • CVE-2016-1219CriApr 20, 2017
    risk 0.64cvss 9.8epss 0.03

    Cybozu Garoon before 4.2.2 allows remote attackers to bypass login authentication via vectors related to API use.

  • CVE-2024-31401CriJun 11, 2024
    risk 0.59cvss 9.0epss 0.01

    Cross-site scripting vulnerability in Cybozu Garoon 5.0.0 to 5.15.2 allows a remote authenticated attacker with an administrative privilege to inject an arbitrary script on the web browser of the user who is logging in to the product.

  • CVE-2019-5931HigMay 17, 2019
    risk 0.57cvss 8.7epss 0.01

    Cybozu Garoon 4.0.0 to 4.6.3 allows authenticated attackers to alter the information with privileges invoking the installer via unspecified vectors.

  • CVE-2018-0607HigJul 26, 2018
    risk 0.57cvss 8.8epss 0.01

    SQL injection vulnerability in the Notifications application in the Cybozu Garoon 3.5.0 to 4.6.2 allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors.

  • CVE-2018-0530HigApr 16, 2018
    risk 0.57cvss 8.8epss 0.01

    SQL injection vulnerability in the Cybozu Garoon 3.5.0 to 4.2.6 allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors.

  • CVE-2016-7803HigJun 9, 2017
    risk 0.57cvss 8.8epss 0.02

    SQL injection vulnerability in the Cybozu Garoon 3.0.0 to 4.2.2 allows remote authenticated attackers to execute arbitrary SQL commands via "MultiReport" function.

  • CVE-2016-4907HigJun 9, 2017
    risk 0.57cvss 8.8epss 0.01

    Cybozu Garoon 3.0.0 to 4.2.2 allow remote attackers to obtain CSRF tokens via unspecified vectors.

  • CVE-2016-1218HigApr 20, 2017
    risk 0.57cvss 8.8epss 0.02

    SQL injection vulnerability in Cybozu Garoon before 4.2.2.

  • CVE-2022-30602HigJul 11, 2022
    risk 0.53cvss 8.1epss 0.01

    Operation restriction bypass in multiple applications of Cybozu Garoon 4.0.0 to 5.9.1 allows a remote authenticated attacker to alter the file information and/or delete the files.

  • CVE-2022-29484HigJul 4, 2022
    risk 0.53cvss 8.1epss 0.01

    Operation restriction bypass vulnerability in Space of Cybozu Garoon 4.0.0 to 5.9.0 allows a remote authenticated attacker to delete the data of Space.

  • CVE-2020-5580HigJun 30, 2020
    risk 0.53cvss 8.1epss 0.01

    Cybozu Garoon 4.0.0 to 5.0.1 allows remote authenticated attackers to bypass access restriction to view and/or alter Single sign-on settings via unspecified vectors.

  • CVE-2018-0673HigNov 15, 2018
    risk 0.53cvss 8.1epss 0.01

    Directory traversal vulnerability in Cybozu Garoon 3.5.0 to 4.6.3 allows authenticated attackers to read arbitrary files via unspecified vectors.

  • CVE-2016-1189HigJun 25, 2016
    risk 0.53cvss 8.1epss 0.01

    Cybozu Garoon 3.x and 4.x before 4.2.1 allows remote authenticated users to bypass intended restrictions on reading, creating, or modifying a portlet via unspecified vectors.

  • CVE-2021-20758HigAug 18, 2021
    risk 0.52cvss 8.0epss 0.00

    Cross-site request forgery (CSRF) vulnerability in Message of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to hijack the authentication of administrators and perform an arbitrary operation via unspecified vectors.

  • CVE-2026-22888HigFeb 2, 2026
    risk 0.49cvss 7.5epss 0.00

    Improper input verification issue exists in Cybozu Garoon 5.0.0 to 6.0.3, which may lead to unauthorized alteration of portal settings, potentially blocking access to the product.

  • CVE-2020-5584HigJun 30, 2020
    risk 0.49cvss 7.5epss 0.01

    Cybozu Garoon 4.0.0 to 5.0.1 allow remote attackers to obtain unintended information via unspecified vectors.

  • CVE-2020-5567HigApr 28, 2020
    risk 0.49cvss 7.5epss 0.01

    Improper authentication vulnerability in Cybozu Garoon 4.0.0 to 4.10.3 allows remote attackers to obtain data in Application Menu.

  • CVE-2019-5991HigSep 12, 2019
    risk 0.49cvss 7.6epss 0.01

    SQL injection vulnerability in the Cybozu Garoon 4.0.0 to 4.10.3 allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors.

  • CVE-2018-16178HigJan 9, 2019
    risk 0.49cvss 7.5epss 0.01

    Cybozu Garoon 3.0.0 to 4.10.0 allows remote attackers to bypass access restriction to view information available only for a sign-on user via Single sign-on function.

Page 1 of 11