Groupsession / Groupsession
20 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-64781 | In GroupSession Free edition prior to ver5.7.1, GroupSession byCloud prior to ver5.7.1, and GroupSession ZION prior to ver5.7.1, "External page display restric… | MEDIUM | 5.1 | Dec 12, 2025 |
| CVE-2025-62192 | SQL Injection vulnerability exists in GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior to ver5.3.3, and GroupSession ZION prior to ver5.… | MEDIUM | 5.3 | Dec 12, 2025 |
| CVE-2025-58576 | Cross-site request forgery vulnerability exists in GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior to ver5.3.3, and GroupSession ZION p… | MEDIUM | 5.1 | Dec 12, 2025 |
| CVE-2025-61987 | GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior to ver5.3.3, and GroupSession ZION prior to ver5.3.2. do not validate origins in WebSoc… | MEDIUM | 6.9 | Dec 12, 2025 |
| CVE-2025-61950 | In GroupSession, a Circular notice can be created with its memo field non-editable, but the authorization check is improperly implemented. With some crafted re… | MEDIUM | 5.3 | Dec 12, 2025 |
| CVE-2025-65120 | Reflected cross-site scripting vulnerability exists in GroupSession Free edition prior to ver5.7.1, GroupSession byCloud prior to ver5.7.1, and GroupSession ZI… | MEDIUM | 5.1 | Dec 12, 2025 |
| CVE-2025-57883 | Reflected cross-site scripting vulnerability exists in GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior to ver5.3.3, and GroupSession ZI… | MEDIUM | 5.1 | Dec 12, 2025 |
| CVE-2025-66284 | Stored cross-site scripting vulnerabilities exist in GroupSession Free edition prior to ver5.7.1, GroupSession byCloud prior to ver5.7.1, and GroupSession ZION… | MEDIUM | 4.8 | Dec 12, 2025 |
| CVE-2025-53523 | Stored cross-site scripting vulnerabilities exist in GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior to ver5.3.3, and GroupSession ZION… | MEDIUM | 4.8 | Dec 12, 2025 |
| CVE-2025-54407 | Stored cross-site scripting vulnerability exists in GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior to ver5.3.3, and GroupSession ZION… | MEDIUM | 5.1 | Dec 12, 2025 |
| CVE-2021-20876 | Path traversal vulnerability in GroupSession Free edition ver5.1.1 and earlier, GroupSession byCloud ver5.1.1 and earlier, and GroupSession ZION ver5.1.1 and e… | MEDIUM | 6.8 | Dec 24, 2021 |
| CVE-2021-20875 | Open redirect vulnerability in GroupSession Free edition ver5.1.1 and earlier, GroupSession byCloud ver5.1.1 and earlier, and GroupSession ZION ver5.1.1 and ea… | MEDIUM | 6.1 | Dec 24, 2021 |
| CVE-2021-20874 | Incorrect permission assignment for critical resource vulnerability in GroupSession Free edition ver5.1.1 and earlier, GroupSession byCloud ver5.1.1 and earlie… | HIGH | 7.5 | Dec 24, 2021 |
| CVE-2021-20789 | Open redirect vulnerability in GroupSession (GroupSession Free edition from ver2.2.0 to the version prior to ver5.1.0, GroupSession byCloud from ver3.0.3 to th… | MEDIUM | 6.1 | Jul 28, 2021 |
| CVE-2021-20788 | Server-side request forgery (SSRF) vulnerability in GroupSession (GroupSession Free edition from ver2.2.0 to the version prior to ver5.1.0, GroupSession byClou… | MEDIUM | 4.3 | Jul 28, 2021 |
| CVE-2021-20787 | Cross-site scripting vulnerability in GroupSession (GroupSession Free edition from ver2.2.0 to the version prior to ver5.1.0, GroupSession byCloud from ver3.0.… | MEDIUM | 4.8 | Jul 28, 2021 |
| CVE-2021-20786 | Cross-site request forgery (CSRF) vulnerability in GroupSession (GroupSession Free edition from ver2.2.0 to the version prior to ver5.1.0, GroupSession byCloud… | MEDIUM | 4.3 | Jul 28, 2021 |
| CVE-2021-20785 | Cross-site scripting vulnerability in GroupSession (GroupSession Free edition from ver2.2.0 to the version prior to ver5.1.0, GroupSession byCloud from ver3.0.… | MEDIUM | 4.8 | Jul 28, 2021 |
| CVE-2017-2166 | Open redirect vulnerability in GroupSession version 4.7.0 and earlier allows an attacker to redirect users to arbitrary web sites and conduct phishing attacks… | MEDIUM | 6.1 | Jan 26, 2018 |
| CVE-2017-2165 | GroupSession versions 4.6.4 and earlier allows remote authenticated attackers to bypass access restrictions to obtain sensitive information such as emails via… | MEDIUM | 6.5 | Jun 9, 2017 |
Showing 1 to 20 of 20 CVEs