VYPR

Groupoffice

by Intermesh

Source repositories

CVEs (30)

  • CVE-2026-25512HigFeb 4, 2026
    risk 0.01cvss 8.8epss 0.03

    Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.150, 25.0.82, and 26.0.5, there is a remote code execution (RCE) vulnerability in Group-Office. The endpoint email/message/tnefAttachmentFromTempFile directly concatenates…

  • CVE-2026-25511MedFeb 4, 2026
    risk 0.00cvss 4.9epss 0.00

    Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.150, 25.0.82, and 26.0.5, an authenticated user within the System Administrator group can trigger a full SSRF via the WOPI service discovery URL, including access to internal…

  • CVE-2026-25134HigFeb 2, 2026
    risk 0.00cvss 8.8epss 0.01

    Group-Office is an enterprise customer relationship management and groupware tool. Prior to 6.8.150, 25.0.82, and 26.0.5, the MaintenanceController exposes an action zipLanguage which takes a lang parameter and passes it directly to a system zip command via exec(). This can be…

  • CVE-2026-23887MedJan 22, 2026
    risk 0.00cvss 5.4epss 0.00

    Group-Office is an enterprise customer relationship management and groupware tool. In versions 6.8.148 and below, and 25.0.1 through 25.0.79, the application stores unsanitized filenames in the database, which can lead to Stored Cross-Site Scripting (XSS). Users who interact…

  • CVE-2025-48993MedJun 17, 2025
    risk 0.00cvss 6.1epss 0.00

    Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.123 and 25.0.27, a malicious JavaScript payload can be executed via the Look and Feel formatting fields. Any user can update their Look and Feel Formatting input fields, but…

  • CVE-2025-48992MedJun 16, 2025
    risk 0.00cvss 4.8epss 0.00

    Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.123 and 25.0.27, a stored and blind cross-site scripting (XSS) vulnerability exists in the Name Field of the user profile. A malicious attacker can change their name to a…

  • CVE-2025-25191MedMar 6, 2025
    risk 0.00cvss 5.4epss 0.00

    Group-Office is an enterprise CRM and groupware tool. This Stored XSS vulnerability exists where user input in the Name field is not properly sanitized before being stored. This vulnerability is fixed in 6.8.100.

  • CVE-2024-22418MedJan 18, 2024
    risk 0.00cvss 6.5epss 0.00

    Group-Office is an enterprise CRM and groupware tool. Affected versions are subject to a vulnerability which is present in the file upload mechanism of Group Office. It allows an attacker to execute arbitrary JavaScript code by embedding it within a file's name. For instance,…

  • CVE-2023-46730HigNov 7, 2023
    risk 0.00cvss 7.4epss 0.01

    Group-Office is an enterprise CRM and groupware tool. In affected versions there is full Server-Side Request Forgery (SSRF) vulnerability in the /api/upload.php endpoint. The /api/upload.php endpoint does not filter URLs which allows a malicious user to cause the server to make…

  • CVE-2007-2720May 16, 2007
    risk 0.00cvss —epss 0.01

    Group-Office before 2.16-13 does not properly validate user IDs, which allows remote attackers to obtain sensitive information via certain requests for (1) message.php and (2) messages.php in modules/email/. NOTE: some of these details are obtained from third party information.

Page 2 of 2