Vulnerability index

Browse CVEs

15 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Group Office HIGH 8.8
CVE-2026-25512EPSS 19%

Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.150, 25.0.82, and 26.0.5, there is a remote …

Fix: 6.8.150 / 25.0.82+
Fix from $1,950 2026-02-04
Group Office HIGH 8.8
CVE-2026-25134

Group-Office is an enterprise customer relationship management and groupware tool. Prior to 6.8.150, 25.0.82, and 26.0.5, the MaintenanceController e…

Fix: 6.8.150 / 25.0.82+
Fix from $1,950 2026-02-02
Group Office MEDIUM 5.4
CVE-2026-23887

Group-Office is an enterprise customer relationship management and groupware tool. In versions 6.8.148 and below, and 25.0.1 through 25.0.79, the app…

Fix: 6.8.149 / 25.0.80+
Fix from $1,600 2026-01-22
Group Office HIGH 8.8
CVE-2025-63406

An issue in Intermesh BV GroupOffice vulnerable before v.25.0.47 and 6.8.136 allows a remote attacker to execute arbitrary code via the dbToApi() and…

Fix: 6.8.136 / 25.0.47+
Fix from $1,950 2025-11-13
Group Office MEDIUM 5.3
CVE-2025-53505

Group-Office versions prior to 6.8.119 and prior to 25.0.20 provided by Intermesh BV contain a path traversal vulnerability. If this vulnerability is…

Fix: 6.8.119 / 25.0.20+
Fix from $1,600 2025-08-21
Group Office MEDIUM 5.4
CVE-2025-53504

Group-Office versions prior to 6.8.119 and prior to 25.0.20 provided by Intermesh BV contain a cross-site scripting vulnerability. If this vulnerabil…

Fix: 6.8.119 / 25.0.20+
Fix from $1,600 2025-08-21
Group Office MEDIUM 5.4
CVE-2025-25191

Group-Office is an enterprise CRM and groupware tool. This Stored XSS vulnerability exists where user input in the Name field is not properly sanitiz…

Patch available
Fix from $1,600 2025-03-06
Group Office MEDIUM 5.4
CVE-2024-23941

Cross-site scripting vulnerability exists in Group Office prior to v6.6.182, prior to v6.7.64 and prior to v6.8.31, which may allow a remote authenti…

Fix: 6.6.182 / 6.7.64+
Fix from $1,600 2024-02-01
Group Office MEDIUM 5.4
CVE-2024-22418

Group-Office is an enterprise CRM and groupware tool. Affected versions are subject to a vulnerability which is present in the file upload mechanism …

Fix: 6.8.29+
Fix from $1,600 2024-01-18
Group Office HIGH 8.8
CVE-2023-46730

Group-Office is an enterprise CRM and groupware tool. In affected versions there is full Server-Side Request Forgery (SSRF) vulnerability in the /api…

Fix: 6.6.177 / 6.7.54+
Fix from $1,950 2023-11-07
Group Office MEDIUM 6.1
CVE-2023-25292

Reflected Cross Site Scripting (XSS) in Intermesh BV Group-Office version 6.6.145, allows attackers to gain escalated privileges and gain sensitive i…

No fix yet
Fix from $1,600 2023-04-27
Group Office MEDIUM 6.1
CVE-2020-35419

Cross Site Scripting (XSS) in Group Office CRM 6.4.196 via the SET_LANGUAGE parameter.

No fix yet
Fix from $1,600 2021-04-14
Group Office MEDIUM 5.3
CVE-2021-28060

A Server-Side Request Forgery (SSRF) vulnerability in Group Office 6.4.196 allows a remote attacker to forge GET requests to arbitrary URLs via the u…

No fix yet
Fix from $1,600 2021-04-14
Group Office MEDIUM 5.4
CVE-2020-35418

Cross Site Scripting (XSS) in the contact page of Group Office CRM 6.4.196 by uploading a crafted svg file.

No fix yet
Fix from $1,600 2021-04-14
Groupoffice MEDIUM 6.5
CVE-2012-4240

SQL injection vulnerability in modules/calendar/json.php in Group-Office community before 4.0.90 allows remote authenticated users to execute arbitra…

Fix: after 4.0.89
Fix from $1,600 2014-09-11