Groupoffice
Intermesh · 19 CVEs
Group-Office: Authenticated Stored XSS in Administrator Context via Arbitrary Cross-User Setting Write
May 29, 2026
Group-Office: Authenticated Remote Code Execution via PHP Insecure Deserialization in `AbstractSettingsCollection`
Apr 2, 2026
Authenticated SQL Injection in Contact/query addressBookIds filter
Mar 27, 2026
Group-Office: Reflected XSS in JavaScript context
Mar 6, 2026
Group-Office: Self XSS in GroupOffice Installer License Page (install/license.php)
Mar 6, 2026
Group-Office Vulnerable to Remote Code Execution (RCE)
Feb 27, 2026
Group-Office Has Authenticated SQL Injection in advancedQueryData.comparator
Feb 27, 2026
Group-Office is vulnerable to SSRF and File Read in WOPI service discovery
Feb 4, 2026
Group-Office is vulnerable to RCE due to Command Injection via TNEF Attachment Handler
Feb 4, 2026
Group-Office Argument Injection in MaintenanceController::actionZipLanguage
Feb 2, 2026
Group-Office has stored XSS vulnerability via unsanitized filenames
Jan 21, 2026
Group-Office vulnerable to reflected XSS via Look and Feel Formatting input
Jun 17, 2025
Group-Office vulnerable to blind XSS
Jun 16, 2025
GroupOffice vulnerable to Stored XSS in Tasks Comment Section
May 22, 2025
GroupOffice's DOM-Based XSS in all Date Input Fields Allows Arbitrary JavaScript Execution
May 22, 2025
GroupOffice's Blind Stored XSS in Phone Number Field Enables Forced Redirect and Unauthorized Actions
May 22, 2025
Group-Office has a Stored XSS Vulnerability via user's name field
Mar 6, 2025
Stored Cross-site Scripting Vulnerability via Malicious File Names in GroupOffice
Jan 18, 2024
Server-Side Request Forgery in groupoffice
Nov 7, 2023
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-45551 | Group-Office: Authenticated Stored XSS in Administrator Context via Arbitrary Cross-User Setting Write | MEDIUM | 0.39% | May 29, 2026 |
| CVE-2026-34838 | Group-Office: Authenticated Remote Code Execution via PHP Insecure Deserialization in `AbstractSettingsCollection` | CRITICAL | 0.99% | Apr 2, 2026 |
| CVE-2026-33755 | Authenticated SQL Injection in Contact/query addressBookIds filter | HIGH | 0.46% | Mar 27, 2026 |
| CVE-2026-30238 | Group-Office: Reflected XSS in JavaScript context | MEDIUM | 0.33% | Mar 6, 2026 |
| CVE-2026-30237 | Group-Office: Self XSS in GroupOffice Installer License Page (install/license.php) | LOW | 0.27% | Mar 6, 2026 |
| CVE-2026-27947 | Group-Office Vulnerable to Remote Code Execution (RCE) | CRITICAL | 1.04% | Feb 27, 2026 |
| CVE-2026-27832 | Group-Office Has Authenticated SQL Injection in advancedQueryData.comparator | HIGH | 0.46% | Feb 27, 2026 |
| CVE-2026-25511 | Group-Office is vulnerable to SSRF and File Read in WOPI service discovery | HIGH | 0.47% | Feb 4, 2026 |
| CVE-2026-25512 | Group-Office is vulnerable to RCE due to Command Injection via TNEF Attachment Handler | CRITICAL | 3.81% | Feb 4, 2026 |
| CVE-2026-25134 | Group-Office Argument Injection in MaintenanceController::actionZipLanguage | CRITICAL | 0.90% | Feb 2, 2026 |
| CVE-2026-23887 | Group-Office has stored XSS vulnerability via unsanitized filenames | MEDIUM | 0.28% | Jan 21, 2026 |
| CVE-2025-48993 | Group-Office vulnerable to reflected XSS via Look and Feel Formatting input | MEDIUM | 0.25% | Jun 17, 2025 |
| CVE-2025-48992 | Group-Office vulnerable to blind XSS | MEDIUM | 0.26% | Jun 16, 2025 |
| CVE-2025-48369 | GroupOffice vulnerable to Stored XSS in Tasks Comment Section | MEDIUM | 0.26% | May 22, 2025 |
| CVE-2025-48368 | GroupOffice's DOM-Based XSS in all Date Input Fields Allows Arbitrary JavaScript Execution | MEDIUM | 0.26% | May 22, 2025 |
| CVE-2025-48366 | GroupOffice's Blind Stored XSS in Phone Number Field Enables Forced Redirect and Unauthorized Actions | MEDIUM | 0.27% | May 22, 2025 |
| CVE-2025-25191 | Group-Office has a Stored XSS Vulnerability via user's name field | MEDIUM | 0.28% | Mar 6, 2025 |
| CVE-2024-22418 | Stored Cross-site Scripting Vulnerability via Malicious File Names in GroupOffice | MEDIUM | 0.42% | Jan 18, 2024 |
| CVE-2023-46730 | Server-Side Request Forgery in groupoffice | HIGH | 0.60% | Nov 7, 2023 |
Showing 1 to 19 of 19 CVEs