Known Vulnerabilities for Groundhogg by Groundhogg Inc.
Listed below are 10 of the newest known vulnerabilities associated with "Groundhogg" by "Groundhogg Inc.".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-57667 json | Sales Representative SQL Injection in Groundhogg <= 4.5 versions. | Not Provided | 2026-06-26 | 2026-06-26 |
| CVE-2026-40793 json | Subscriber Broken Access Control in Groundhogg < 4.4.1 versions. | Not Provided | 2026-06-15 | 2026-06-15 |
| CVE-2026-40727 json | Sales Representative Arbitrary File Deletion in Groundhogg <= 4.4 versions. | Not Provided | 2026-06-15 | 2026-06-15 |
| CVE-2026-13333 json | The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection via... | Not Provided | 2026-06-27 | 2026-06-27 |
| CVE-2026-13331 json | The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection via... | Not Provided | 2026-06-27 | 2026-06-27 |
| CVE-2026-13226 json | The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection via... | Not Provided | 2026-06-26 | 2026-06-26 |
| CVE-2025-54053 json | Deserialization of Untrusted Data vulnerability in Adrian Tobey Groundhogg groundhogg allows Object Injection.This issue affe... | Not Provided | 2025-08-20 | 2026-04-23 |
| CVE-2025-48300 json | Unrestricted Upload of File with Dangerous Type vulnerability in Adrian Tobey Groundhogg groundhogg allows Upload a Web Shell... | Not Provided | 2025-07-16 | 2026-04-23 |
| CVE-2024-56289 json | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Adrian Tobey Groundhogg... | Not Provided | 2025-01-07 | 2026-04-23 |
| CVE-2024-37235 json | Cross-Site Request Forgery (CSRF) vulnerability in Adrian Tobey Groundhogg groundhogg allows Cross Site Request Forgery.This ... | Not Provided | 2025-01-02 | 2026-04-23 |