Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Groundhogg — Vulnerabilities & Security Advisories 14

All 14 CVE vulnerabilities found in Groundhogg, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for the product Groundhogg, specifically focusing on weakness types and associated security tags within the product category. It collects a comprehensive history of reported security flaws, covering advisories published over the most recent three-year window. Readers can use this resource to track the vendor's advisory history, analyze specific weakness classes affecting the software, and examine the product's long-term vulnerability patterns without needing to search individual databases.

Vendor: Groundhogg Inc.

CVE ID Title CVSS Severity Published
CVE-2026-85310 WordPress Groundhogg plugin <= 4.7.1 - Path Traversal vulnerability CWE-35 6.5 Medium 2026-09-10
CVE-2026-57389 WordPress Groundhogg plugin <= 4.4.1 - Arbitrary File Deletion vulnerability CWE-22 8.6 High 2026-07-13
CVE-2026-57667 WordPress Groundhogg plugin <= 4.5 - SQL Injection vulnerability CWE-89 8.5 High 2026-06-26
CVE-2026-40793 WordPress Groundhogg plugin < 4.4.1 - Broken Access Control vulnerability CWE-862 6.5 Medium 2026-06-15
CVE-2026-40727 WordPress Groundhogg plugin <= 4.4 - Arbitrary File Deletion vulnerability CWE-22 7.7 High 2026-06-15
CVE-2025-64367 WordPress Groundhogg plugin <= 4.2.6 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium 2025-10-31
CVE-2025-54053 WordPress Groundhogg plugin <= 4.2.2 - PHP Object Injection vulnerability CWE-502 6.6 Medium 2025-08-20
CVE-2025-48300 WordPress Groundhogg plugin <= 4.2.1 - Arbitrary File Upload vulnerability CWE-434 9.1 Critical 2025-07-16
CVE-2024-56289 WordPress Groundhogg plugin <= 3.7.3.3 - Reflected Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High 2025-01-07
CVE-2024-37235 WordPress Groundhogg plugin <= 3.4.2.3 - Cross Site Request Forgery (CSRF) vulnerability CWE-352 4.3 Medium 2025-01-02
CVE-2024-37264 WordPress Groundhogg plugin <= 3.4.2.3 - Reflected Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High 2024-07-22
CVE-2023-34178 WordPress Groundhogg Plugin <= 2.7.11 is vulnerable to Cross Site Request Forgery (CSRF) CWE-352 5.4 Medium 2023-11-09
CVE-2023-34179 WordPress Groundhogg Plugin <= 2.7.11 is vulnerable to SQL Injection CWE-89 7.6 High 2023-11-03
CVE-2023-40681 WordPress Groundhogg Plugin <= 2.7.11.10 is vulnerable to Cross Site Scripting (XSS) CWE-79 5.9 Medium 2023-10-31

All 14 known CVE vulnerabilities affecting Groundhogg with full Chinese analysis, references, and POCs where available.