← Vulnerability feed

Vulnerability record · CVE-2008-3650 · published 13 August 2008

CVE-2008-3650: Horde groupware webmail edition vulnerability

Horde · Groupware Webmail Edition

Multiple unspecified vulnerabilities in Horde Groupware Webmail before Edition 1.1.1 (final) have unknown impact and attack vectors related to "unescaped output," possibly cross-site scripting (XSS), in the (1) object browser and (2) contact view.

9.0 CVSS 2.0 High EPSS 1.0% · top 38.0%
9.0CVSS 2.0 base score
1.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
16 Jun 2026Last modified by NVD

Description

Multiple unspecified vulnerabilities in Horde Groupware Webmail before Edition 1.1.1 (final) have unknown impact and attack vectors related to "unescaped output," possibly cross-site scripting (XSS), in the (1) object browser and (2) contact view.

AV:N/AC:L/Au:S/C:C/I:C/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2008-3650 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2008-7218Horde groupware vulnerabilityUnspecified vulnerability in the Horde API in Horde 3.1 before 3.1.6 and 3.2 before 3.2 before 3.2-RC2; Turba H3 2.1 before 2.1.6 and 2.2 before 2.2-…EPSS 2.2%10.0CVE-2008-7219Horde groupware permissions and access controls vulnerabilityHorde Kronolith H3 2.1 before 2.1.7 and 2.2 before 2.2-RC2; Nag H3 2.1 before 2.1.4 and 2.2 before 2.2-RC2; Mnemo H3 2.1 before 2.1.2 and H3 2.2 befo…EPSS 2.7%6.0CVE-2008-1284Horde groupware path traversal vulnerabilityDirectory traversal vulnerability in Horde 3.1.6, Groupware before 1.0.5, and Groupware Webmail Edition before 1.0.6, when running with certain confi…EPSS 1.7%5.8CVE-2007-6018Horde framework permissions and access controls vulnerabilityIMP Webmail Client 4.1.5, Horde Application Framework 3.1.5, and Horde Groupware Webmail Edition 1.0.3 does not validate unspecified HTTP requests, w…EPSS 1.8%4.9CVE-2008-0807Horde groupware permissions and access controls vulnerabilitylib/Driver/sql.php in Turba 2 (turba2) Contact Manager H3 2.1.x before 2.1.7 and 2.2.x before 2.2-RC3, as used in products such as Horde Groupware be…EPSS 1.4%4.3CVE-2012-0791Horde dynamic imp cross-site scripting vulnerabilityMultiple cross-site scripting (XSS) vulnerabilities in Horde IMP before 5.0.18 and Horde Groupware Webmail Edition before 4.0.6 allow remote attacker…EPSS 2.3%4.3CVE-2012-0909Horde groupware webmail edition cross-site scripting vulnerabilityCross-site scripting (XSS) vulnerability in Horde_Form in Horde Groupware Webmail Edition before 4.0.6 allows remote attackers to inject arbitrary we…EPSS 1.8%4.3CVE-2008-2783Horde groupware cross-site scripting vulnerabilityMultiple cross-site scripting (XSS) vulnerabilities in Horde Groupware, Groupware Webmail Edition, and Kronolith allow remote attackers to inject arb…EPSS 1.5%

Source: NIST National Vulnerability Database (record CVE-2008-3650), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.