CVE-2016-4866: Cybozu Office

Medium severity, CVSS 4.8. EPSS: 0.8% chance of exploitation in the next 30 days.

Cross-site scripting vulnerability in Cybozu Office 9.0.0 to 10.4.0 allows attackers with administrator rights to inject arbitrary web script or HTML via the Project function.

Affected products

  • Cybozu Office: version 9.0 only; version 9.1.0 only; version 9.2.0 only; version 9.2.1 only; version 9.3.0 only; version 9.3.1 only; …

Published 2017-04-17. Last modified 2026-06-17.