VYPR

Garoon

by Cybozu

CVEs (201)

  • CVE-2016-1193HigJun 25, 2016
    risk 0.49cvss 7.5epss 0.01

    Cybozu Garoon 3.7 through 4.2 allows remote attackers to obtain sensitive email-reading information via unspecified vectors.

  • CVE-2016-1195HigJun 19, 2016
    risk 0.48cvss 7.4epss 0.02

    Open redirect vulnerability in Cybozu Garoon 3.x and 4.x before 4.2.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL.

  • CVE-2019-5934HigMay 17, 2019
    risk 0.47cvss 7.2epss 0.01

    SQL injection vulnerability in the Cybozu Garoon 4.0.0 to 4.10.0 allows attacker with administrator rights to execute arbitrary SQL commands via the Log Search function of application 'logging'.

  • CVE-2026-57279MedAug 10, 2026
    risk 0.44cvss 6.8epss 0.00

    Cybozu Garoon contains a cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed in the web browser of a user logged in to the product.

  • CVE-2024-31399MedJun 11, 2024
    risk 0.42cvss 6.5epss 0.00

    Excessive platform resource consumption within a loop issue exists in Cybozu Garoon 5.0.0 to 5.15.2. If this vulnerability is exploited, processing a crafted mail may cause a denial-of-service (DoS) condition.

  • CVE-2024-31400MedJun 11, 2024
    risk 0.42cvss 6.5epss 0.00

    Insertion of sensitive information into sent data issue exists in Cybozu Garoon 5.0.0 to 5.15.0. If this vulnerability is exploited, unintended data may be left in forwarded mail.

  • CVE-2023-26595MedMay 23, 2023
    risk 0.42cvss 6.5epss 0.01

    Denial-of-service (DoS) vulnerability in Message of Cybozu Garoon 4.10.0 to 5.9.2 allows a remote authenticated attacker to cause a denial of service condition.

  • CVE-2022-29512MedJul 11, 2022
    risk 0.42cvss 6.5epss 0.01

    Exposure of sensitive information to an unauthorized actor issue in multiple applications of Cybozu Garoon 4.0.0 to 5.9.1 allows a remote authenticated attacker to obtain the data without the viewing privilege.

  • CVE-2022-29892MedJul 4, 2022
    risk 0.42cvss 6.5epss 0.01

    Improper input validation vulnerability in Space of Cybozu Garoon 4.0.0 to 5.5.1 allows a remote authenticated attacker to repeatedly display errors in certain functions and cause a denial-of-service (DoS).

  • CVE-2020-5643MedNov 6, 2020
    risk 0.42cvss 6.5epss 0.02

    Improper input validation vulnerability in Cybozu Garoon 5.0.0 to 5.0.2 allows a remote authenticated attacker to delete some data of the bulletin board via unspecified vector.

  • CVE-2020-5587MedJun 30, 2020
    risk 0.42cvss 6.5epss 0.01

    Cybozu Garoon 4.0.0 to 5.0.1 allow remote authenticated attackers to obtain unintended information via unspecified vectors.

  • CVE-2020-5583MedJun 30, 2020
    risk 0.42cvss 6.5epss 0.01

    Cybozu Garoon 4.0.0 to 5.0.1 allows remote authenticated attackers to bypass access restriction to obtain unauthorized Multi-Report's data via unspecified vectors.

  • CVE-2020-5581MedJun 30, 2020
    risk 0.42cvss 6.5epss 0.02

    Path traversal vulnerability in Cybozu Garoon 4.0.0 to 5.0.1 allows remote authenticated attackers to obtain unintended information via unspecified vectors.

  • CVE-2016-7802MedJun 9, 2017
    risk 0.42cvss 6.5epss 0.02

    Directory traversal vulnerability in Cybozu Garoon 3.0.0 to 4.2.2 allows remote authenticated attackers to read arbitrary files via unspecified vectors.

  • CVE-2016-1194MedApr 21, 2017
    risk 0.42cvss 6.5epss 0.02

    Cybozu Garoon before 4.2.1 allows remote attackers to cause a denial of service.

  • CVE-2016-1190MedJun 25, 2016
    risk 0.42cvss 6.5epss 0.01

    Cybozu Garoon 3.1 through 4.2 allows remote authenticated users to bypass intended restrictions on MultiReport reading via unspecified vectors.

  • CVE-2016-1188MedJun 25, 2016
    risk 0.42cvss 6.5epss 0.01

    Cybozu Garoon 3.x and 4.x before 4.2.1 allows remote authenticated users to send spoofed e-mail messages via unspecified vectors.

  • CVE-2026-20711MedFeb 2, 2026
    risk 0.40cvss 6.1epss 0.00

    Cross-site scripting vulnerability exists in E-mail function of Cybozu Garoon 5.0.0 to 6.0.3, which may allow an attacker to reset arbitrary users’ passwords.

  • CVE-2022-27627MedJul 4, 2022
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting vulnerability in Organization's Information of Cybozu Garoon 4.10.2 to 5.5.1 allows a remote attacker to execute an arbitrary script on the logged-in user's web browser.

  • CVE-2021-20771MedAug 18, 2021
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting vulnerability in some functions of E-Mail of Cybozu Garoon 4.0.0 to 5.5.0 allows a remote attacker to inject an arbitrary script via unspecified vectors.

Page 2 of 11