CVE-2019-12094: Horde Groupware

Medium severity, CVSS 6.1. EPSS: 1.5% chance of exploitation in the next 30 days.

Horde Groupware Webmail Edition through 5.2.22 allows XSS via an admin/user.php?form=update_f&user_name= or admin/user.php?form=remove_f&user_name= or admin/config/diff.php?app= URI.

Affected products

  • Horde Groupware: up to and including 5.2.22

Published 2019-10-24. Last modified 2026-06-17.