Known Vulnerabilities for products from EGroupware

Listed below are 20 of the newest known vulnerabilities associated with the vendor "EGroupware".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2026-40187 json Not Provided 2026-07-20 2026-07-20
CVE-2026-27823 json Not Provided 2026-07-20 2026-07-20
CVE-2023-38328 json An issue was discovered in eGroupWare 17.1.20190111. An Improper Password Storage vulnerability affects the setup panel of un... 4.9 - MEDIUM 2023-10-26 2023-11-07
CVE-2017-14920 json Stored XSS vulnerability in eGroupware Community Edition before 16.1.20170922 allows an unauthenticated remote attacker to in... 6.1 - MEDIUM 2017-09-30 2017-10-05
CVE-2014-2988 json EGroupware Enterprise Line (EPL) before 1.1.20140505, EGroupware Community Edition before 1.8.007.20140506, and EGroupware be... Not Provided 2014-10-27 2026-05-06
CVE-2014-2987 json Multiple cross-site request forgery (CSRF) vulnerabilities in EGroupware Enterprise Line (EPL) before 1.1.20140505, EGroupwar... Not Provided 2014-10-26 2026-05-06
CVE-2014-2027 json eGroupware before 1.8.006.20140217 allows remote attackers to conduct PHP object injection attacks, delete arbitrary files, a... Not Provided 2015-03-31 2026-05-06
CVE-2012-2211 json Cross-site scripting (XSS) vulnerability in phpgwapi/inc/common_functions_inc.php in eGroupware before 1.8.004.20120405 allow... Not Provided 2012-11-22 2026-04-29
CVE-2011-4951 json Open redirect vulnerability in phpgwapi/ntlm/index.php in EGroupware Enterprise Line (EPL) before 11.1.20110804-1 and EGroupw... Not Provided 2012-08-31 2026-04-29
CVE-2011-4950 json Cross-site scripting (XSS) vulnerability in phpgwapi/js/jscalendar/test.php in EGroupware Enterprise Line (EPL) before 11.1.2... Not Provided 2012-08-31 2026-04-29
CVE-2011-4949 json SQL injection vulnerability in phpgwapi/js/dhtmlxtree/samples/with_db/loaddetails.php in EGroupware Enterprise Line (EPL) bef... Not Provided 2012-08-31 2026-04-29
CVE-2011-4948 json Directory traversal vulnerability in admin/remote.php in EGroupware Enterprise Line (EPL) before 11.1.20110804-1 and EGroupwa... Not Provided 2012-08-31 2026-04-29
CVE-2010-3314 json Cross-site scripting (XSS) vulnerability in login.php in EGroupware 1.4.001+.002; 1.6.001+.002 and possibly other versions be... Not Provided 2010-09-22 2026-04-29
CVE-2010-3313 json phpgwapi/js/fckeditor/editor/dialog/fck_spellerpages/spellerpages/serverscripts/spellchecker.php in EGroupware 1.4.001+.002; ... Not Provided 2010-09-22 2026-04-29
CVE-2008-2041 json Multiple unspecified vulnerabilities in eGroupWare before 1.4.004 have unspecified attack vectors and "grave" impact when the... Not Provided 2008-04-30 2026-04-23
CVE-2008-1502 json The _bad_protocol_once function in phpgwapi/inc/class.kses.inc.php in KSES, as used in eGroupWare before 1.4.003, Moodle befo... Not Provided 2008-03-25 2026-04-23
CVE-2007-5091 json Multiple cross-site scripting (XSS) vulnerabilities in eGroupWare 1.4.001 allow remote attackers to inject arbitrary web scri... Not Provided 2007-09-26 2026-04-23
CVE-2007-3155 json Unspecified vulnerability in eGroupWare before 1.2.107-2 has unknown impact and attack vectors related to ADOdb. NOTE: due t... Not Provided 2007-06-11 2026-04-23
CVE-2007-3154 json Unspecified vulnerability in Walter Zorn wz_tooltip.js (aka wz_tooltips) before 4.01, as used by eGroupWare before 1.2.107-2 ... Not Provided 2007-06-11 2026-04-23
CVE-2005-1203 json Multiple SQL injection vulnerabilities in index.php in eGroupware before 1.0.0.007 allow remote attackers to execute arbitrar... Not Provided 2005-05-02 2025-04-03

Known software with vulnerabilities from EGroupware

Type Vendor Product Version
ApplicationEgroupwareEgroupware1.8.001.20110421
ApplicationEgroupwareEgroupware Enterprise Line11.1.20110711-1

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report