📦 Garoon

by Cybozu

🔍 What is Garoon?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-31401

CRITICAL CVSS 9.0 Jun 11, 2024

This is a cross-site scripting (XSS) vulnerability in Cybozu Garoon that allows authenticated administrators to inject malicious scripts into web pages. When exploited, these scripts execute in the br...

CVE-2026-22888

HIGH CVSS 7.5 Feb 2, 2026

An improper input verification vulnerability in Cybozu Garoon allows attackers to modify portal settings without proper authorization. This could block legitimate users from accessing the system. Affe...

CVE-2022-30602

HIGH CVSS 8.1 Jul 11, 2022

This vulnerability allows authenticated remote attackers to bypass operation restrictions in Cybozu Garoon, enabling them to alter file information and delete files. It affects all users of Cybozu Gar...

CVE-2021-20758

HIGH CVSS 8.0 Aug 18, 2021

This CSRF vulnerability in Cybozu Garoon allows authenticated attackers to trick administrators into performing unintended actions by exploiting their active sessions. It affects all Garoon users with...

CVE-2026-20711

MEDIUM CVSS 6.1 Feb 2, 2026

A cross-site scripting vulnerability in the email function of Cybozu Garoon allows attackers to inject malicious scripts that can reset arbitrary users' passwords. This affects organizations using Cyb...

CVE-2026-22881

MEDIUM CVSS 5.4 Feb 2, 2026

A cross-site scripting vulnerability in the Message function of Cybozu Garoon allows attackers to inject malicious scripts that can reset arbitrary users' passwords. This affects Cybozu Garoon version...

CVE-2024-39457

MEDIUM CVSS 5.4 Jul 19, 2024

This vulnerability allows attackers to inject malicious scripts into PDF previews in Cybozu Garoon. When exploited, these scripts execute in the browsers of logged-in users, potentially stealing sessi...

CVE-2024-31397

MEDIUM CVSS 4.9 Jun 11, 2024

An improper handling of extra values vulnerability in Cybozu Garoon allows authenticated administrators to cause a denial-of-service condition. This affects users with administrative privileges on vul...

CVE-2024-31398

MEDIUM CVSS 4.3 Jun 11, 2024

This vulnerability in Cybozu Garoon allows authenticated users to access sensitive user list information that should be restricted. It affects all users who can log into vulnerable versions of the sof...

CVE-2024-31402

MEDIUM CVSS 4.3 Jun 11, 2024

An incorrect authorization vulnerability in Cybozu Garoon allows authenticated users to delete Shared To-Do data they shouldn't have access to. This affects organizations using Garoon versions 5.0.0 t...

CVE-2024-31404

MEDIUM CVSS 4.3 Jun 11, 2024

This vulnerability in Cybozu Garoon allows authenticated users to view sensitive Scheduler data they shouldn't have access to. It affects users who can log into Garoon versions 5.5.0 through 6.0.0. Th...