Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Groundhogg — CRM, Newsletters, and Marketing Automation — Vulnerabilities & Security Advisories 16

All 16 CVE vulnerabilities found in Groundhogg — CRM, Newsletters, and Marketing Automation, with AI-generated Chinese analysis, references, and POCs.

This page documents known security vulnerabilities and weaknesses affecting the Groundhogg CRM, Newsletters, and Marketing Automation software platform. It aggregates data on specific flaw types identified in this vendor’s products, providing a centralized resource for tracking issues related to this particular software ecosystem. The content compiled here encompasses a wide range of vulnerability categories, including but not limited to injection flaws, authentication bypasses, cross-site scripting, and insecure direct object references. The historical data spans from the initial release of the software through the present day, offering a comprehensive timeline of security incidents. This time range allows users to observe trends in code quality and the vendor’s responsiveness to emerging threats over multiple years of development and updates. Visitors to this page can effectively track the vendor’s security advisories to stay informed about critical patches and known risks. Users can also gain a deeper understanding of common weakness classes that impact marketing automation tools by analyzing the recurring patterns in reported issues. Furthermore, the archive serves as a reference for looking up the product’s vulnerability history, enabling security professionals, developers, and compliance officers to assess the overall security posture of Groundhogg. By reviewing past incidents, stakeholders can make more informed decisions regarding the deployment and maintenance of this marketing platform, ensuring that potential risks are mitigated through up-to-date information and historical context.

Vendor: trainingbusinesspros

CVE ID Title CVSS Severity Published
CVE-2026-18387 Groundhogg <= 4.5.14 - Authenticated (Vendor+) SQL Injection via 'tag_query' Parameter CWE-89 6.5 Medium 2026-08-15
CVE-2026-11454 Groundhogg — CRM, Newsletters, and Marketing Automation <= 4.5.2 - Insecure Direct Object Reference CWE-639 6.5 Medium 2026-08-05
CVE-2026-14029 Groundhogg <= 4.5.8 - Authenticated (Custom+) SQL Injection via 'select' Parameter CWE-89 6.5 Medium 2026-07-02
CVE-2026-13333 Groundhogg <= 4.5.5 - Authenticated (Sales Rep+) SQL Injection via 'query[select]' Parameter CWE-89 6.5 Medium 2026-06-27
CVE-2026-13331 Groundhogg <= 4.5.5 - Authenticated (Marketer+) SQL Injection via 'search' Parameter CWE-89 6.5 Medium 2026-06-27
CVE-2026-13226 Groundhogg <= 4.5.4 - Authenticated (Custom+) SQL Injection via 'after' Parameter CWE-89 6.5 Medium 2026-06-26
CVE-2025-12750 Groundhogg <= 4.2.6.1 - Authenticated (Admin+) SQL Injection CWE-89 4.9 Medium 2025-11-21
CVE-2025-4206 WordPress CRM, Email & Marketing Automation for WordPress | Award Winner — Groundhogg <= 4.1.1.2 - Authenticated (Administrator+) Arbitrary File Deletion CWE-22 7.2 High 2025-05-09
CVE-2025-1267 Groundhogg <= 3.7.4.1 - Authenticated (Administrator+) Stored Cross-Site Scripting via label Parameter CWE-79 5.5 Medium 2025-04-01
CVE-2025-0394 Groundhogg <= 3.7.3.5 - Authenticated (Author+) Arbitrary File Upload via gh_big_file_upload Function CWE-434 8.8 High 2025-01-14
CVE-2023-2717 Groundhogg <= 2.7.9.8 - Cross-Site Request Forgery to Disable All Plugins CWE-352 5.4 Medium 2023-05-20
CVE-2023-2736 Groundhogg <= 2.7.9.8 - Cross-Site Request Forgery to Privilege Escalation CWE-352 7.5 High 2023-05-20
CVE-2023-2735 Groundhogg <= 2.7.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode CWE-79 4.9 Medium 2023-05-20
CVE-2023-2716 Groundhogg <= 2.7.9.8 - Missing Authorization to Non-Arbitrary File Upload CWE-862 5.4 Medium 2023-05-20
CVE-2023-2714 Groundhogg <= 2.7.9.8 - Missing Authorization to Update License CWE-862 4.3 Medium 2023-05-20
CVE-2023-2715 Groundhogg <= 2.7.9.8 - Missing Authorization to Admin Account and Ticket Creation CWE-862 4.3 Medium 2023-05-20

All 16 known CVE vulnerabilities affecting Groundhogg — CRM, Newsletters, and Marketing Automation with full Chinese analysis, references, and POCs where available.