Vulnerability index

Browse CVEs

17 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2026-22243 EGroupware is a Web based groupware server written in PHP. A SQL Injection vulnerability exists in the core components of EGroupware prior to version… Egroupware 23.1.20260113 / 26.0.20260113+ Fix from $1,9502026-01-28 MEDIUM 6.1 CVE-2023-38329 An issue was discovered in eGroupWare 17.1.20190111. A cross-site scripting Reflected (XSS) vulnerability exists in calendar/freebusy.php, which allo… Egroupware Mitigation only Fix from $1,6002025-07-11 MEDIUM 5.3 CVE-2023-38327 An issue was discovered in eGroupWare 17.1.20190111. A User Enumeration vulnerability exists under calendar/freebusy.php, which allows unauthenticate… Egroupware Mitigation only Fix from $1,6002025-07-11 CRITICAL 9.8 CVE-2024-40614 EGroupware before 23.1.20240624 mishandles an ORDER BY clause. This leads to json.php?menuaction=EGroupware\Api\Etemplate\Widget\Nextmatch::ajax_get_… Egroupware 23.1.20240624+ Fix from $2,3002024-07-07 MEDIUM 6.1 CVE-2017-14920 Stored XSS vulnerability in eGroupware Community Edition before 16.1.20170922 allows an unauthenticated remote attacker to inject JavaScript via the … Egroupware after 16.1.20170703 Fix from $1,6002017-09-30 HIGH 7.5 CVE-2014-2027 eGroupware before 1.8.006.20140217 allows remote attackers to conduct PHP object injection attacks, delete arbitrary files, and possibly execute arbi… Egroupware after 1.8006 Fix from $1,9502015-03-31 HIGH 8.5 CVE-2014-2988 EGroupware Enterprise Line (EPL) before 1.1.20140505, EGroupware Community Edition before 1.8.007.20140506, and EGroupware before 14.1 beta allows re… Egroupware after 1.8006 Fix from $1,9502014-10-27 MEDIUM 6.8 CVE-2014-2987 Multiple cross-site request forgery (CSRF) vulnerabilities in EGroupware Enterprise Line (EPL) before 1.1.20140505, EGroupware Community Edition befo… Egroupware after 1.8006 Fix from $1,6002014-10-26 HIGH 7.5 CVE-2011-4949 SQL injection vulnerability in phpgwapi/js/dhtmlxtree/samples/with_db/loaddetails.php in EGroupware Enterprise Line (EPL) before 11.1.20110804-1 and … Egroupware after 11.1.20110711-1 Fix from $1,9502012-08-31 MEDIUM 5.8 CVE-2011-4951 Open redirect vulnerability in phpgwapi/ntlm/index.php in EGroupware Enterprise Line (EPL) before 11.1.20110804-1 and EGroupware Community Edition be… Egroupware after 11.1.20110711-1 Fix from $1,6002012-08-31 MEDIUM 5.0 CVE-2011-4948 Directory traversal vulnerability in admin/remote.php in EGroupware Enterprise Line (EPL) before 11.1.20110804-1 and EGroupware Community Edition bef… Egroupware after 11.1.20110711-1 Fix from $1,6002012-08-31 HIGH 7.5 CVE-2010-3313EPSS 9% phpgwapi/js/fckeditor/editor/dialog/fck_spellerpages/spellerpages/serverscripts/spellchecker.php in EGroupware 1.4.001+.002; 1.6.001+.002 and possibl… Egroupware Patch available Fix from $1,9502010-09-22 HIGH 10.0 CVE-2008-2041 Multiple unspecified vulnerabilities in eGroupWare before 1.4.004 have unspecified attack vectors and "grave" impact when the web server has write ac… Egroupware after 1.4.003 Fix from $1,9502008-04-30 HIGH 10.0 CVE-2007-3154 Unspecified vulnerability in Walter Zorn wz_tooltip.js (aka wz_tooltips) before 4.01, as used by eGroupWare before 1.2.107-2 and other packages, has … Egroupware after 1.2.106-2 Fix from $1,9502007-06-11 HIGH 10.0 CVE-2007-3155 Unspecified vulnerability in eGroupWare before 1.2.107-2 has unknown impact and attack vectors related to ADOdb. NOTE: due to lack of details from t… Egroupware after 1.2.106-2 Fix from $1,9502007-06-11 HIGH 7.5 CVE-2005-1203 Multiple SQL injection vulnerabilities in index.php in eGroupware before 1.0.0.007 allow remote attackers to execute arbitrary SQL commands via the (… Egroupware Patch available Fix from $1,9502005-05-02 MEDIUM 6.8 CVE-2005-1202 Multiple cross-site scripting (XSS) vulnerabilities in eGroupware before 1.0.0.007 allow remote attackers to inject arbitrary web script or HTML via … Egroupware Patch available Fix from $1,6002005-05-02