← Vulnerability feed

Vulnerability record · CVE-2012-0909 · published 24 January 2012

CVE-2012-0909: Horde groupware webmail edition cross-site scripting vulnerability

Horde · Groupware Webmail Edition

Cross-site scripting (XSS) vulnerability in Horde_Form in Horde Groupware Webmail Edition before 4.0.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to email verification. NOTE: Some of these details are obtained from third party information.

4.3 CVSS 2.0 Medium EPSS 1.8% · top 22.6% CWE-79 · Cross-site scripting
4.3CVSS 2.0 base score
1.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Cross-site scripting (XSS) vulnerability in Horde_Form in Horde Groupware Webmail Edition before 4.0.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to email verification. NOTE: Some of these details are obtained from third party information.

AV:N/AC:M/Au:N/C:N/I:P/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-0909 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2008-7218Horde groupware vulnerabilityUnspecified vulnerability in the Horde API in Horde 3.1 before 3.1.6 and 3.2 before 3.2 before 3.2-RC2; Turba H3 2.1 before 2.1.6 and 2.2 before 2.2-…EPSS 2.2%10.0CVE-2008-7219Horde groupware permissions and access controls vulnerabilityHorde Kronolith H3 2.1 before 2.1.7 and 2.2 before 2.2-RC2; Nag H3 2.1 before 2.1.4 and 2.2 before 2.2-RC2; Mnemo H3 2.1 before 2.1.2 and H3 2.2 befo…EPSS 2.7%9.0CVE-2008-3650Horde groupware webmail edition vulnerabilityMultiple unspecified vulnerabilities in Horde Groupware Webmail before Edition 1.1.1 (final) have unknown impact and attack vectors related to "unesc…EPSS 1.0%6.0CVE-2008-1284Horde groupware path traversal vulnerabilityDirectory traversal vulnerability in Horde 3.1.6, Groupware before 1.0.5, and Groupware Webmail Edition before 1.0.6, when running with certain confi…EPSS 1.7%5.8CVE-2007-6018Horde framework permissions and access controls vulnerabilityIMP Webmail Client 4.1.5, Horde Application Framework 3.1.5, and Horde Groupware Webmail Edition 1.0.3 does not validate unspecified HTTP requests, w…EPSS 1.8%4.9CVE-2008-0807Horde groupware permissions and access controls vulnerabilitylib/Driver/sql.php in Turba 2 (turba2) Contact Manager H3 2.1.x before 2.1.7 and 2.2.x before 2.2-RC3, as used in products such as Horde Groupware be…EPSS 1.4%4.3CVE-2012-0791Horde dynamic imp cross-site scripting vulnerabilityMultiple cross-site scripting (XSS) vulnerabilities in Horde IMP before 5.0.18 and Horde Groupware Webmail Edition before 4.0.6 allow remote attacker…EPSS 2.3%4.3CVE-2008-2783Horde groupware cross-site scripting vulnerabilityMultiple cross-site scripting (XSS) vulnerabilities in Horde Groupware, Groupware Webmail Edition, and Kronolith allow remote attackers to inject arb…EPSS 1.5%

Source: NIST National Vulnerability Database (record CVE-2012-0909), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.