Known Vulnerabilities for products from Egroupware
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Egroupware".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-40187 json | Not Provided | 2026-07-20 | 2026-07-20 | |
| CVE-2026-27823 json | Not Provided | 2026-07-20 | 2026-07-21 | |
| CVE-2023-38328 json | An issue was discovered in eGroupWare 17.1.20190111. An Improper Password Storage vulnerability affects the setup panel of un... | 4.9 - MEDIUM | 2023-10-26 | 2023-11-07 |
| CVE-2017-14920 json | Stored XSS vulnerability in eGroupware Community Edition before 16.1.20170922 allows an unauthenticated remote attacker to in... | 6.1 - MEDIUM | 2017-09-30 | 2017-10-05 |
| CVE-2014-2988 json | EGroupware Enterprise Line (EPL) before 1.1.20140505, EGroupware Community Edition before 1.8.007.20140506, and EGroupware be... | Not Provided | 2014-10-27 | 2026-05-06 |
| CVE-2014-2987 json | Multiple cross-site request forgery (CSRF) vulnerabilities in EGroupware Enterprise Line (EPL) before 1.1.20140505, EGroupwar... | Not Provided | 2014-10-26 | 2026-05-06 |
| CVE-2014-2027 json | eGroupware before 1.8.006.20140217 allows remote attackers to conduct PHP object injection attacks, delete arbitrary files, a... | Not Provided | 2015-03-31 | 2026-05-06 |
| CVE-2012-2211 json | Cross-site scripting (XSS) vulnerability in phpgwapi/inc/common_functions_inc.php in eGroupware before 1.8.004.20120405 allow... | Not Provided | 2012-11-22 | 2026-04-29 |
| CVE-2011-4951 json | Open redirect vulnerability in phpgwapi/ntlm/index.php in EGroupware Enterprise Line (EPL) before 11.1.20110804-1 and EGroupw... | Not Provided | 2012-08-31 | 2026-04-29 |
| CVE-2011-4950 json | Cross-site scripting (XSS) vulnerability in phpgwapi/js/jscalendar/test.php in EGroupware Enterprise Line (EPL) before 11.1.2... | Not Provided | 2012-08-31 | 2026-04-29 |
| CVE-2011-4949 json | SQL injection vulnerability in phpgwapi/js/dhtmlxtree/samples/with_db/loaddetails.php in EGroupware Enterprise Line (EPL) bef... | Not Provided | 2012-08-31 | 2026-04-29 |
| CVE-2011-4948 json | Directory traversal vulnerability in admin/remote.php in EGroupware Enterprise Line (EPL) before 11.1.20110804-1 and EGroupwa... | Not Provided | 2012-08-31 | 2026-04-29 |
| CVE-2010-3314 json | Cross-site scripting (XSS) vulnerability in login.php in EGroupware 1.4.001+.002; 1.6.001+.002 and possibly other versions be... | Not Provided | 2010-09-22 | 2026-04-29 |
| CVE-2010-3313 json | phpgwapi/js/fckeditor/editor/dialog/fck_spellerpages/spellerpages/serverscripts/spellchecker.php in EGroupware 1.4.001+.002; ... | Not Provided | 2010-09-22 | 2026-04-29 |
| CVE-2008-2041 json | Multiple unspecified vulnerabilities in eGroupWare before 1.4.004 have unspecified attack vectors and "grave" impact when the... | Not Provided | 2008-04-30 | 2026-04-23 |
| CVE-2008-1502 json | The _bad_protocol_once function in phpgwapi/inc/class.kses.inc.php in KSES, as used in eGroupWare before 1.4.003, Moodle befo... | Not Provided | 2008-03-25 | 2026-04-23 |
| CVE-2007-5091 json | Multiple cross-site scripting (XSS) vulnerabilities in eGroupWare 1.4.001 allow remote attackers to inject arbitrary web scri... | Not Provided | 2007-09-26 | 2026-04-23 |
| CVE-2007-3155 json | Unspecified vulnerability in eGroupWare before 1.2.107-2 has unknown impact and attack vectors related to ADOdb. NOTE: due t... | Not Provided | 2007-06-11 | 2026-04-23 |
| CVE-2007-3154 json | Unspecified vulnerability in Walter Zorn wz_tooltip.js (aka wz_tooltips) before 4.01, as used by eGroupWare before 1.2.107-2 ... | Not Provided | 2007-06-11 | 2026-04-23 |
| CVE-2005-1203 json | Multiple SQL injection vulnerabilities in index.php in eGroupware before 1.0.0.007 allow remote attackers to execute arbitrar... | Not Provided | 2005-05-02 | 2025-04-03 |
Known software with vulnerabilities from Egroupware
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Egroupware | Egroupware | 1.8.001.20110421 |
| Application | Egroupware | Egroupware Enterprise Line | 11.1.20110711-1 |