CVE-2026-22888
- EPSS 0.02%
- Veröffentlicht 02.02.2026 06:37:33
- Zuletzt bearbeitet 19.02.2026 14:53:03
Improper input verification issue exists in Cybozu Garoon 5.0.0 to 6.0.3, which may lead to unauthorized alteration of portal settings, potentially blocking access to the product.
CVE-2026-22881
- EPSS 0.01%
- Veröffentlicht 02.02.2026 06:37:17
- Zuletzt bearbeitet 19.02.2026 15:00:54
Cross-site scripting vulnerability exists in Message function of Cybozu Garoon 5.15.0 to 6.0.3, which may allow an attacker to reset arbitrary users’ passwords.
CVE-2026-20711
- EPSS 0.01%
- Veröffentlicht 02.02.2026 06:37:05
- Zuletzt bearbeitet 19.02.2026 15:06:02
Cross-site scripting vulnerability exists in E-mail function of Cybozu Garoon 5.0.0 to 6.0.3, which may allow an attacker to reset arbitrary users’ passwords.
CVE-2024-39457
- EPSS 0.83%
- Veröffentlicht 19.07.2024 09:15:05
- Zuletzt bearbeitet 19.03.2025 21:15:36
Cybozu Garoon 6.0.0 to 6.0.1 contains a cross-site scripting vulnerability in PDF preview. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user’s web browser.
CVE-2024-31397
- EPSS 0.12%
- Veröffentlicht 11.06.2024 06:15:10
- Zuletzt bearbeitet 13.02.2026 15:30:05
Improper handling of extra values issue exists in Cybozu Garoon 5.0.0 to 5.15.2. If this vulnerability is exploited, a user who can log in to the product with the administrative privilege may be able to cause a denial-of-service (DoS) condition.
CVE-2024-31398
- EPSS 0.49%
- Veröffentlicht 11.06.2024 06:15:10
- Zuletzt bearbeitet 13.03.2025 14:15:25
Insertion of sensitive information into sent data issue exists in Cybozu Garoon 5.0.0 to 5.15.2. If this vulnerability is exploited, a user who can log in to the product may obtain information on the list of users.
CVE-2024-31399
- EPSS 0.25%
- Veröffentlicht 11.06.2024 06:15:10
- Zuletzt bearbeitet 20.03.2025 19:15:29
Excessive platform resource consumption within a loop issue exists in Cybozu Garoon 5.0.0 to 5.15.2. If this vulnerability is exploited, processing a crafted mail may cause a denial-of-service (DoS) condition.
CVE-2024-31402
- EPSS 0.37%
- Veröffentlicht 11.06.2024 06:15:10
- Zuletzt bearbeitet 28.03.2025 21:15:16
Incorrect authorization vulnerability in Cybozu Garoon 5.0.0 to 5.15.2 allows a remote authenticated attacker to delete the data of Shared To-Dos.
CVE-2024-31400
- EPSS 0.48%
- Veröffentlicht 11.06.2024 05:15:53
- Zuletzt bearbeitet 05.08.2025 15:37:51
Insertion of sensitive information into sent data issue exists in Cybozu Garoon 5.0.0 to 5.15.0. If this vulnerability is exploited, unintended data may be left in forwarded mail.
- EPSS 3.46%
- Veröffentlicht 11.06.2024 05:15:53
- Zuletzt bearbeitet 05.08.2025 15:30:18
Cross-site scripting vulnerability in Cybozu Garoon 5.0.0 to 5.15.2 allows a remote authenticated attacker with an administrative privilege to inject an arbitrary script on the web browser of the user who is logging in to the product.