Skip to main content

Vendor/product archive

egroupware / egroupware CVEs

Beta · best-effort

25 CVEs tagged to egroupware / egroupware4 Critical, 6 High, 14 Medium, 1 Low, 0 Unrated.

CVE-2026-22243

Published Jan 28, 2026

EGroupware is a Web based groupware server written in PHP. A SQL Injection vulnerability exists in the core components of EGroupware prior to versions 23.1.20260113 and 26.0.20260…

CVSS 8.7 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2023-38329

Published Jul 11, 2025

An issue was discovered in eGroupWare 17.1.20190111. A cross-site scripting Reflected (XSS) vulnerability exists in calendar/freebusy.php, which allows unauthenticated remote atta…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-38327

Published Jul 11, 2025

An issue was discovered in eGroupWare 17.1.20190111. A User Enumeration vulnerability exists under calendar/freebusy.php, which allows unauthenticated remote attackers to enumerat…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-40614

Published Jul 7, 2024

EGroupware before 23.1.20240624 mishandles an ORDER BY clause. This leads to json.php?menuaction=EGroupware\Api\Etemplate\Widget\Nextmatch::ajax_get_rows sort.id SQL injection by…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-38328

Published Oct 26, 2023

An issue was discovered in eGroupWare 17.1.20190111. An Improper Password Storage vulnerability affects the setup panel of under setup/manageheader.php, which allows authenticated…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-14920

Published Sep 30, 2017

Stored XSS vulnerability in eGroupware Community Edition before 16.1.20170922 allows an unauthenticated remote attacker to inject JavaScript via the User-Agent HTTP header, which…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-2027

Published Mar 31, 2015

eGroupware before 1.8.006.20140217 allows remote attackers to conduct PHP object injection attacks, delete arbitrary files, and possibly execute arbitrary code via the (1) addr_fi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-2988

Published Oct 27, 2014

EGroupware Enterprise Line (EPL) before 1.1.20140505, EGroupware Community Edition before 1.8.007.20140506, and EGroupware before 14.1 beta allows remote authenticated administrat…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-2987

Published Oct 26, 2014

Multiple cross-site request forgery (CSRF) vulnerabilities in EGroupware Enterprise Line (EPL) before 1.1.20140505, EGroupware Community Edition before 1.8.007.20140506, and EGrou…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-2211

Published Nov 22, 2012

Cross-site scripting (XSS) vulnerability in phpgwapi/inc/common_functions_inc.php in eGroupware before 1.8.004.20120405 allows remote attackers to inject arbitrary web script or H…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3314

Published Sep 22, 2010

Cross-site scripting (XSS) vulnerability in login.php in EGroupware 1.4.001+.002; 1.6.001+.002 and possibly other versions before 1.6.003; and EPL 9.1 before 9.1.20100309 and 9.2…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3313

Published Sep 22, 2010

phpgwapi/js/fckeditor/editor/dialog/fck_spellerpages/spellerpages/serverscripts/spellchecker.php in EGroupware 1.4.001+.002; 1.6.001+.002 and possibly other versions before 1.6.00…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-2041

Published Apr 30, 2008

Multiple unspecified vulnerabilities in eGroupWare before 1.4.004 have unspecified attack vectors and "grave" impact when the web server has write access to a directory under the…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-1502

Published Mar 25, 2008

The _bad_protocol_once function in phpgwapi/inc/class.kses.inc.php in KSES, as used in eGroupWare before 1.4.003, Moodle before 1.8.5, and other products, allows remote attackers…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5091

Published Sep 26, 2007

Multiple cross-site scripting (XSS) vulnerabilities in eGroupWare 1.4.001 allow remote attackers to inject arbitrary web script or HTML via the cat_data[color] parameter to (1) pr…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-3154

Published Jun 11, 2007

Unspecified vulnerability in Walter Zorn wz_tooltip.js (aka wz_tooltips) before 4.01, as used by eGroupWare before 1.2.107-2 and other packages, has unknown impact and remote atta…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-3155

Published Jun 11, 2007

Unspecified vulnerability in eGroupWare before 1.2.107-2 has unknown impact and attack vectors related to ADOdb. NOTE: due to lack of details from the vendor, it is uncertain whe…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2005-1129

Published May 2, 2005

eGroupWare 1.0.6 and earlier, when an e-mail is composed with an attachment but not sent, will send that attachment in the next e-mail, which may cause sensitive information to be…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2005-1202

Published May 2, 2005

Multiple cross-site scripting (XSS) vulnerabilities in eGroupware before 1.0.0.007 allow remote attackers to inject arbitrary web script or HTML via the (1) ab_id, (2) page, (3) t…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-1203

Published May 2, 2005

Multiple SQL injection vulnerabilities in index.php in eGroupware before 1.0.0.007 allow remote attackers to execute arbitrary SQL commands via the (1) filter or (2) cats_app para…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-1467

Published Dec 31, 2004

Multiple cross-site scripting (XSS) vulnerabilities in eGroupWare 1.0.00.003 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) date or search text…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 25 CVEsPage 1 of 1