Group-Office
Intermesh · 13 CVEs
Group-Office: Authenticated Remote Code Execution via PHP Insecure Deserialization in `AbstractSettingsCollection`
Apr 2, 2026
Authenticated SQL Injection in Contact/query addressBookIds filter
Mar 27, 2026
Group-Office: Reflected XSS in JavaScript context
Mar 6, 2026
Group-Office: Self XSS in GroupOffice Installer License Page (install/license.php)
Mar 6, 2026
Group-Office Vulnerable to Remote Code Execution (RCE)
Feb 27, 2026
Group-Office Has Authenticated SQL Injection in advancedQueryData.comparator
Feb 27, 2026
Group-Office versions prior to 6.8.119 and prior to 25.0.20 provided by Intermesh BV contain a path traversal vulnerabi…
Aug 21, 2025
Group-Office versions prior to 6.8.119 and prior to 25.0.20 provided by Intermesh BV contain a cross-site scripting vul…
Aug 21, 2025
Group-Office vulnerable to reflected XSS via Look and Feel Formatting input
Jun 17, 2025
Group-Office vulnerable to blind XSS
Jun 16, 2025
GroupOffice vulnerable to Stored XSS in Tasks Comment Section
May 22, 2025
GroupOffice's DOM-Based XSS in all Date Input Fields Allows Arbitrary JavaScript Execution
May 22, 2025
GroupOffice's Blind Stored XSS in Phone Number Field Enables Forced Redirect and Unauthorized Actions
May 22, 2025
Server-Side Request Forgery in groupoffice
Nov 7, 2023
SQL injection vulnerability in modules/notes/json.php in Intermesh Group-Office 3.5.9 allows remote attackers to execut…
Sep 16, 2010
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-34838 | Group-Office: Authenticated Remote Code Execution via PHP Insecure Deserialization in `AbstractSettingsCollection` | CRITICAL | 0.99% | Apr 2, 2026 |
| CVE-2026-33755 | Authenticated SQL Injection in Contact/query addressBookIds filter | HIGH | 0.46% | Mar 27, 2026 |
| CVE-2026-30238 | Group-Office: Reflected XSS in JavaScript context | MEDIUM | 0.33% | Mar 6, 2026 |
| CVE-2026-30237 | Group-Office: Self XSS in GroupOffice Installer License Page (install/license.php) | LOW | 0.27% | Mar 6, 2026 |
| CVE-2026-27947 | Group-Office Vulnerable to Remote Code Execution (RCE) | CRITICAL | 1.04% | Feb 27, 2026 |
| CVE-2026-27832 | Group-Office Has Authenticated SQL Injection in advancedQueryData.comparator | HIGH | 0.46% | Feb 27, 2026 |
| CVE-2025-53505 | Group-Office versions prior to 6.8.119 and prior to 25.0.20 provided by Intermesh BV contain a path traversal vulnerability. If this vulnerability is exploited… | MEDIUM | 0.34% | Aug 21, 2025 |
| CVE-2025-53504 | Group-Office versions prior to 6.8.119 and prior to 25.0.20 provided by Intermesh BV contain a cross-site scripting vulnerability. If this vulnerability is exp… | MEDIUM | 0.19% | Aug 21, 2025 |
| CVE-2025-48993 | Group-Office vulnerable to reflected XSS via Look and Feel Formatting input | MEDIUM | 0.25% | Jun 17, 2025 |
| CVE-2025-48992 | Group-Office vulnerable to blind XSS | MEDIUM | 0.26% | Jun 16, 2025 |
| CVE-2025-48369 | GroupOffice vulnerable to Stored XSS in Tasks Comment Section | MEDIUM | 0.26% | May 22, 2025 |
| CVE-2025-48368 | GroupOffice's DOM-Based XSS in all Date Input Fields Allows Arbitrary JavaScript Execution | MEDIUM | 0.26% | May 22, 2025 |
| CVE-2025-48366 | GroupOffice's Blind Stored XSS in Phone Number Field Enables Forced Redirect and Unauthorized Actions | MEDIUM | 0.27% | May 22, 2025 |
| CVE-2023-46730 | Server-Side Request Forgery in groupoffice | HIGH | 0.60% | Nov 7, 2023 |
| CVE-2010-3428 | SQL injection vulnerability in modules/notes/json.php in Intermesh Group-Office 3.5.9 allows remote attackers to execute arbitrary SQL commands via the categor… | HIGH | 0.96% | Sep 16, 2010 |
Showing 1 to 13 of 13 CVEs