VendorsGroup Officegroup_officeall versions
Vulnerabilities

Group Office Group Office

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

15CVEs
CVE-2026-25512
Group-Office is vulnerable to RCE due to Command Injection via TNEF Attachment Handler
Published 2026-02-04 · Analyzed
9.4EPSS 0.035
CVE-2026-25134
Group-Office Argument Injection in MaintenanceController::actionZipLanguage
Published 2026-02-02 · Analyzed
9.4EPSS 0.008
CVE-2025-63406
An issue in Intermesh BV GroupOffice vulnerable before v.25.0.47 and 6.8.136 allows a remote attacker to execute arbitrary code via the dbToApi() and eval() in the FunctionField.php
Published 2025-11-13 · Analyzed
8.8EPSS 0.007
CVE-2023-46730
Server-Side Request Forgery in groupoffice
Published 2023-11-07 · Modified
8.8EPSS 0.006
CVE-2026-25511
Group-Office is vulnerable to SSRF and File Read in WOPI service discovery
Published 2026-02-04 · Analyzed
8.2EPSS 0.004
CVE-2025-25191
Group-Office has a Stored XSS Vulnerability via user's name field
Published 2025-03-06 · Analyzed
6.9EPSS 0.003
CVE-2024-22418
Stored Cross-site Scripting Vulnerability via Malicious File Names in GroupOffice
Published 2024-01-18 · Modified
6.5EPSS 0.004
CVE-2020-35419
Cross Site Scripting (XSS) in Group Office CRM 6.4.196 via the SET_LANGUAGE parameter.
Published 2021-04-14 · Modified
6.1EPSS 0.007
CVE-2023-25292
Reflected Cross Site Scripting (XSS) in Intermesh BV Group-Office version 6.6.145, allows attackers to gain escalated privileges and gain sensitive information via the GO_LANGUAGE cookie.
Published 2023-04-27 · Modified
6.1EPSS 0.006
CVE-2024-23941
Cross-site scripting vulnerability exists in Group Office prior to v6.6.182, prior to v6.7.64 and prior to v6.8.31, which may allow a remote authenticated attacker to execute an arbitrary script on the web browser of the user who is logging in to the product.
Published 2024-02-01 · Modified
5.4EPSS 0.006
CVE-2020-35418
Cross Site Scripting (XSS) in the contact page of Group Office CRM 6.4.196 by uploading a crafted svg file.
Published 2021-04-14 · Modified
5.4EPSS 0.005
CVE-2026-23887
Group-Office has stored XSS vulnerability via unsanitized filenames
Published 2026-01-21 · Analyzed
5.4EPSS 0.003
CVE-2025-53504
Group-Office versions prior to 6.8.119 and prior to 25.0.20 provided by Intermesh BV contain a cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed in the user's web browser.
Published 2025-08-21 · Analyzed
5.4EPSS 0.002
CVE-2021-28060
A Server-Side Request Forgery (SSRF) vulnerability in Group Office 6.4.196 allows a remote attacker to forge GET requests to arbitrary URLs via the url parameter to group/api/upload.php.
Published 2021-04-14 · Modified
5.3EPSS 0.014
CVE-2025-53505
Group-Office versions prior to 6.8.119 and prior to 25.0.20 provided by Intermesh BV contain a path traversal vulnerability. If this vulnerability is exploited, information on the server hosting the product may be exposed.
Published 2025-08-21 · Analyzed
5.3EPSS 0.003