← Vulnerability feed

Vulnerability record · CVE-2008-7218 · published 13 September 2009

CVE-2008-7218: Horde groupware vulnerability

Horde · Groupware

Unspecified vulnerability in the Horde API in Horde 3.1 before 3.1.6 and 3.2 before 3.2 before 3.2-RC2; Turba H3 2.1 before 2.1.6 and 2.2 before 2.2-RC2; Kronolith H3 2.1 before 2.1.7 and H3 2.2 before 2.2-RC2; Nag H3 2.1 before 2.1.4 and 2.2 before 2.2-RC2; Mnemo H3 2.1 before 2.1.2 and 2.2 before 2.2-RC2; Horde Groupware 1.0 before 1.0.3 and 1.1 before 1.1-RC2; and Groupware Webmail Edition 1.0 before 1.0.4 and 1.1 before 1.1-RC2 has unknown impact and attack vectors.

10.0 CVSS 2.0 High EPSS 2.2% · top 18.2%
10.0CVSS 2.0 base score
2.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
7Affected product versions listed by NVD
38References
16 Jun 2026Last modified by NVD

Description

Unspecified vulnerability in the Horde API in Horde 3.1 before 3.1.6 and 3.2 before 3.2 before 3.2-RC2; Turba H3 2.1 before 2.1.6 and 2.2 before 2.2-RC2; Kronolith H3 2.1 before 2.1.7 and H3 2.2 before 2.2-RC2; Nag H3 2.1 before 2.1.4 and 2.2 before 2.2-RC2; Mnemo H3 2.1 before 2.1.2 and 2.2 before 2.2-RC2; Horde Groupware 1.0 before 1.0.3 and 1.1 before 1.1-RC2; and Groupware Webmail Edition 1.0 before 1.0.4 and 1.1 before 1.1-RC2 has unknown impact and attack vectors.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Affected products

7 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://lists.horde.org/archives/announce/2008/000360.html Patch
http://lists.horde.org/archives/announce/2008/000361.html
http://lists.horde.org/archives/announce/2008/000362.html Patch
http://lists.horde.org/archives/announce/2008/000363.html Patch
http://lists.horde.org/archives/announce/2008/000364.html Patch
http://lists.horde.org/archives/announce/2008/000365.html Patch
http://lists.horde.org/archives/announce/2008/000366.html Patch
http://lists.horde.org/archives/announce/2008/000367.html Patch
http://lists.horde.org/archives/announce/2008/000368.html Patch
http://lists.horde.org/archives/announce/2008/000369.html Patch
http://lists.horde.org/archives/announce/2008/000371.html Patch
http://lists.horde.org/archives/announce/2008/000374.html Patch
http://lists.horde.org/archives/announce/2008/000376.html Patch
http://lists.horde.org/archives/announce/2008/000377.html Patch
http://secunia.com/advisories/28382 Vendor Advisory
http://www.osvdb.org/42775
http://www.securityfocus.com/bid/27217
https://exchange.xforce.ibmcloud.com/vulnerabilities/39599
https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00176.html
http://lists.horde.org/archives/announce/2008/000360.html Patch
http://lists.horde.org/archives/announce/2008/000361.html
http://lists.horde.org/archives/announce/2008/000362.html Patch
http://lists.horde.org/archives/announce/2008/000363.html Patch
http://lists.horde.org/archives/announce/2008/000364.html Patch
http://lists.horde.org/archives/announce/2008/000365.html Patch
http://lists.horde.org/archives/announce/2008/000366.html Patch
http://lists.horde.org/archives/announce/2008/000367.html Patch
http://lists.horde.org/archives/announce/2008/000368.html Patch
http://lists.horde.org/archives/announce/2008/000369.html Patch
http://lists.horde.org/archives/announce/2008/000371.html Patch
http://lists.horde.org/archives/announce/2008/000374.html Patch
http://lists.horde.org/archives/announce/2008/000376.html Patch
http://lists.horde.org/archives/announce/2008/000377.html Patch
http://secunia.com/advisories/28382 Vendor Advisory
http://www.osvdb.org/42775
http://www.securityfocus.com/bid/27217
https://exchange.xforce.ibmcloud.com/vulnerabilities/39599
https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00176.html

Track CVE-2008-7218 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2008-7219Horde groupware permissions and access controls vulnerabilityHorde Kronolith H3 2.1 before 2.1.7 and 2.2 before 2.2-RC2; Nag H3 2.1 before 2.1.4 and 2.2 before 2.2-RC2; Mnemo H3 2.1 before 2.1.2 and H3 2.2 befo…EPSS 2.7%10.0CVE-2005-3344Horde vulnerabilityThe default installation of Horde 3.0.4 contains an administrative account with a blank password, which allows remote attackers to gain access.EPSS 8.0%9.8CVE-2020-8518Horde Groupware Webmail CSV import PHP code injectionHorde Groupware Webmail Edition 5.2.22 permits injection of arbitrary PHP code through CSV data, resulting in remote code execution. The flaw is a co…EPSS 72%analysed9.0CVE-2008-3650Horde groupware webmail edition vulnerabilityMultiple unspecified vulnerabilities in Horde Groupware Webmail before Edition 1.1.1 (final) have unknown impact and attack vectors related to "unesc…EPSS 1.0%8.8CVE-2013-6364Horde groupware cross-site scripting vulnerabilityHorde Groupware Webmail Edition has CSRF and XSS when saving search as a virtual address bookEPSS 2.1%8.8CVE-2019-12095Horde groupware cross-site scripting vulnerabilityHorde Trean, as used in Horde Groupware Webmail Edition through 5.2.22 and other products, allows CSRF, as demonstrated by the treanBookmarkTags para…EPSS 1.1%8.8CVE-2019-9858Horde groupware path traversal vulnerabilityRemote code execution was discovered in Horde Groupware Webmail 5.2.22 and 5.2.17. Horde/Form/Type.php contains a vulnerable class that handles image…EPSS 19%8.8CVE-2017-7413Horde groupware os command injection vulnerabilityIn Horde_Crypt before 2.7.6, as used in Horde Groupware Webmail Edition through 5.2.17, OS Command Injection can occur if the attacker is an authenti…EPSS 40%

Source: NIST National Vulnerability Database (record CVE-2008-7218), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.