Known Vulnerabilities for products from Phpgroupware

Listed below are 20 of the newest known vulnerabilities associated with the vendor "Phpgroupware".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2010-0404 json Multiple SQL injection vulnerabilities in phpGroupWare (phpgw) before 0.9.16.016 allow remote attackers to execute arbitrary ... Not Provided 2010-05-19 2026-04-29
CVE-2010-0403 json Directory traversal vulnerability in about.php in phpGroupWare (phpgw) before 0.9.16.016 allows remote attackers to include a... Not Provided 2010-05-19 2026-04-29
CVE-2009-4416 json Cross-site scripting (XSS) vulnerability in login.php in phpGroupWare 0.9.16.12, and possibly other versions before 0.9.16.01... Not Provided 2009-12-24 2026-04-23
CVE-2009-4415 json Multiple directory traversal vulnerabilities in phpGroupWare 0.9.16.12, and possibly other versions before 0.9.16.014, allow ... Not Provided 2009-12-24 2026-04-23
CVE-2009-4414 json SQL injection vulnerability in phpgwapi /inc/class.auth_sql.inc.php in phpGroupWare 0.9.16.12, and possibly other versions be... Not Provided 2009-12-24 2026-04-23
CVE-2006-4458 json Directory traversal vulnerability in calendar/inc/class.holidaycalc.inc.php in phpGroupWare 0.9.16.010 and earlier allows rem... 6.4 - MEDIUM 2006-08-31 2017-10-19
CVE-2005-3347 json Multiple directory traversal vulnerabilities in index.php in phpSysInfo 2.4 and earlier, as used in phpgroupware 0.9.16 and e... Not Provided 2005-11-18 2025-04-03
CVE-2005-2761 json Cross-site scripting (XSS) vulnerability in phpGroupWare 0.9.16.000 allows administrators to inject arbitrary web script or H... Not Provided 2005-08-31 2025-04-03
CVE-2004-2578 json phpGroupWare before 0.9.16.002 transmits the (1) header admin and (2) setup passwords in plaintext via cookies, which allows ... Not Provided 2004-12-31 2025-04-03
CVE-2004-2577 json The acl_check function in phpGroupWare 0.9.16RC2 always returns True, even when mkdir does not behave as expected, which coul... Not Provided 2004-12-31 2025-04-03
CVE-2004-2576 json class.vfs_dav.inc.php in phpGroupWare 0.9.16.000 does not create .htaccess files to enable authorization checks for access to... Not Provided 2004-12-31 2025-04-03
CVE-2004-2575 json phpGroupWare 0.9.14.005 and earlier allow remote attackers to obtain sensitive information via a direct request to (1) hook_a... Not Provided 2004-12-31 2025-04-03
CVE-2004-2574 json Cross-site scripting (XSS) vulnerability in index.php in phpGroupWare 0.9.14.005 and earlier allows remote attackers to injec... Not Provided 2004-12-31 2025-04-03
CVE-2004-2573 json PHP remote file inclusion vulnerability in tables_update.inc.php in phpGroupWare 0.9.14.005 and earlier allows remote attacke... Not Provided 2004-12-31 2025-04-03
CVE-2004-2407 json Unknown vulnerability in phpGroupWare before 0.9.14.002 has unknown attack vectors and impact, related to a "security hole" i... Not Provided 2004-12-31 2025-04-03
CVE-2004-2406 json Unknown "overflow" in the phpgw_config table for phpGroupWare before 0.9.14.002 has unknown attack vectors and impact. Not Provided 2004-12-31 2025-04-03
CVE-2004-1385 json phpGroupWare 0.9.16.003 and earlier allows remote attackers to gain sensitive information via (1) unexpected characters in th... Not Provided 2004-12-31 2025-04-03
CVE-2004-1384 json Multiple cross-site scripting (XSS) vulnerabilities in phpGroupWare 0.9.16.003 and earlier allow remote attackers to inject a... Not Provided 2004-12-31 2025-04-03
CVE-2004-1383 json Multiple SQL injection vulnerabilities in phpGroupWare 0.9.16.003 and earlier allow remote attackers to execute arbitrary SQL... Not Provided 2004-12-31 2025-04-03
CVE-2004-0875 json Multiple cross-site scripting (XSS) vulnerabilities in Phpgroupware (aka webdistro) 0.9.16.002 and earlier allow remote attac... Not Provided 2004-12-23 2025-04-03

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report