CVE Browser

More filters (active)
CVE-2026-45551 MEDIUM

Group-Office: Authenticated Stored XSS in Administrator Context via Arbitrary Cross-User Setting Write

CVSS 5.1 EPSS 0.39% May 29, 2026
CVE-2026-34838 CRITICAL

Group-Office: Authenticated Remote Code Execution via PHP Insecure Deserialization in `AbstractSettingsCollection`

CVSS 10.0 EPSS 0.99% Apr 2, 2026
CVE-2026-33755 HIGH

Authenticated SQL Injection in Contact/query addressBookIds filter

CVSS 8.8 EPSS 0.46% Mar 27, 2026
CVE-2026-30238 MEDIUM

Group-Office: Reflected XSS in JavaScript context

CVSS 5.1 EPSS 0.33% Mar 6, 2026
CVE-2026-30237 LOW

Group-Office: Self XSS in GroupOffice Installer License Page (install/license.php)

CVSS 2.1 EPSS 0.27% Mar 6, 2026
CVE-2026-27947 CRITICAL

Group-Office Vulnerable to Remote Code Execution (RCE)

CVSS 9.4 EPSS 1.04% Feb 27, 2026
CVE-2026-27832 HIGH

Group-Office Has Authenticated SQL Injection in advancedQueryData.comparator

CVSS 7.1 EPSS 0.46% Feb 27, 2026
CVE-2026-25511 HIGH

Group-Office is vulnerable to SSRF and File Read in WOPI service discovery

CVSS 8.2 EPSS 0.47% Feb 4, 2026
CVE-2026-25512 CRITICAL

Group-Office is vulnerable to RCE due to Command Injection via TNEF Attachment Handler

CVSS 9.4 EPSS 3.81% Feb 4, 2026
CVE-2026-25134 CRITICAL

Group-Office Argument Injection in MaintenanceController::actionZipLanguage

CVSS 9.4 EPSS 0.90% Feb 2, 2026
CVE-2026-23887 MEDIUM

Group-Office has stored XSS vulnerability via unsanitized filenames

CVSS 5.1 EPSS 0.28% Jan 21, 2026
CVE-2025-53505 MEDIUM

Group-Office versions prior to 6.8.119 and prior to 25.0.20 provided by Intermesh BV contain a path traversal vulnerability. If this vulnerability is exploited…

CVSS 5.3 EPSS 0.34% Aug 21, 2025
CVE-2025-53504 MEDIUM

Group-Office versions prior to 6.8.119 and prior to 25.0.20 provided by Intermesh BV contain a cross-site scripting vulnerability. If this vulnerability is exp…

CVSS 4.8 EPSS 0.19% Aug 21, 2025
CVE-2025-48993 MEDIUM

Group-Office vulnerable to reflected XSS via Look and Feel Formatting input

CVSS 5.3 EPSS 0.25% Jun 17, 2025
CVE-2025-48992 MEDIUM

Group-Office vulnerable to blind XSS

CVSS 5.2 EPSS 0.26% Jun 16, 2025
CVE-2025-48369 MEDIUM

GroupOffice vulnerable to Stored XSS in Tasks Comment Section

CVSS 5.3 EPSS 0.26% May 22, 2025
CVE-2025-48368 MEDIUM

GroupOffice's DOM-Based XSS in all Date Input Fields Allows Arbitrary JavaScript Execution

CVSS 5.8 EPSS 0.26% May 22, 2025
CVE-2025-48366 MEDIUM

GroupOffice's Blind Stored XSS in Phone Number Field Enables Forced Redirect and Unauthorized Actions

CVSS 6.9 EPSS 0.27% May 22, 2025
CVE-2025-25191 MEDIUM

Group-Office has a Stored XSS Vulnerability via user's name field

CVSS 6.9 EPSS 0.28% Mar 6, 2025
CVE-2024-23941 MEDIUM

Cross-site scripting vulnerability exists in Group Office prior to v6.6.182, prior to v6.7.64 and prior to v6.8.31, which may allow a remote authenticated atta…

CVSS 5.4 EPSS 0.62% Feb 1, 2024
CVE-2024-22418 MEDIUM

Stored Cross-site Scripting Vulnerability via Malicious File Names in GroupOffice

CVSS 6.5 EPSS 0.42% Jan 18, 2024
CVE-2023-46730 HIGH

Server-Side Request Forgery in groupoffice

CVSS 8.8 EPSS 0.60% Nov 7, 2023
CVE-2010-3428 HIGH

SQL injection vulnerability in modules/notes/json.php in Intermesh Group-Office 3.5.9 allows remote attackers to execute arbitrary SQL commands via the categor…

CVSS 7.5 EPSS 0.96% Sep 16, 2010

Showing 1 to 23 CVEs · page 1