Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

groupoffice — Vulnerabilities & Security Advisories 19

All 19 CVE vulnerabilities found in groupoffice, with AI-generated Chinese analysis, references, and POCs.

GroupOffice is a web-based groupware and office collaboration suite developed by Intermesh, and this page aggregates known vulnerabilities associated with this specific product across common weakness classifications such as cross-site scripting, SQL injection, and information disclosure. The collection encompasses security issues reported from the initial release up to the most recent advisories, providing a comprehensive chronological overview of the software's security landscape over time. Here, researchers and administrators can track Intermesh’s security advisories to understand how the vendor addresses critical flaws, explore the structural and code-level weaknesses inherent in web-based collaboration tools, and review the historical trend of vulnerabilities within GroupOffice to assess long-term stability and risk exposure. This resource serves as a centralized reference for evaluating the security posture of the platform, allowing users to identify patterns in recurring defect types and correlate specific software versions with disclosed security incidents. By consolidating disparate reports into a single view, the page facilitates a clearer understanding of the attack surface presented by GroupOffice, enabling better-informed decisions regarding deployment, patching strategies, and risk mitigation in enterprise environments. The data includes both confirmed exploits and theoretical weaknesses, offering a nuanced perspective on the product’s resilience against common web application attacks and highlighting areas where future development should prioritize security hardening.

Vendor: Intermesh

CVE ID Title CVSS Severity Published
CVE-2026-45551 Group-Office: Authenticated Stored XSS in Administrator Context via Arbitrary Cross-User Setting Write CWE-79 - - 2026-05-29
CVE-2026-34838 Group-Office: Authenticated Remote Code Execution via PHP Insecure Deserialization in `AbstractSettingsCollection` CWE-502 10.0 Critical 2026-04-02
CVE-2026-33755 Authenticated SQL Injection in Contact/query addressBookIds filter CWE-89 8.8 High 2026-03-27
CVE-2026-30238 Group-Office: Reflected XSS in JavaScript context CWE-79 6.1 - 2026-03-06
CVE-2026-30237 Group-Office: Self XSS in GroupOffice Installer License Page (install/license.php) CWE-79 6.1 - 2026-03-06
CVE-2026-27947 Group-Office Vulnerable to Remote Code Execution (RCE) CWE-88 8.0 - 2026-02-27
CVE-2026-27832 Group-Office Has Authenticated SQL Injection in advancedQueryData.comparator CWE-89 8.8 - 2026-02-27
CVE-2026-25511 Group-Office is vulnerable to SSRF and File Read in WOPI service discovery CWE-918 6.8AI Medium AI 2026-02-04
CVE-2026-25512 Group-Office is vulnerable to RCE due to Command Injection via TNEF Attachment Handler CWE-78 8.8AI High AI 2026-02-04
CVE-2026-25134 Group-Office Argument Injection in MaintenanceController::actionZipLanguage CWE-88 7.2AI High AI 2026-02-02
CVE-2026-23887 Group-Office has stored XSS vulnerability via unsanitized filenames CWE-79 5.4AI Medium AI 2026-01-21
CVE-2025-48993 Group-Office vulnerable to reflected XSS via Look and Feel Formatting input CWE-79 6.1AI Medium AI 2025-06-17
CVE-2025-48992 Group-Office vulnerable to blind XSS CWE-79 5.4AI Medium AI 2025-06-16
CVE-2025-48369 GroupOffice vulnerable to Stored XSS in Tasks Comment Section CWE-79 5.4AI Medium AI 2025-05-22
CVE-2025-48368 GroupOffice's DOM-Based XSS in all Date Input Fields Allows Arbitrary JavaScript Execution CWE-79 6.1AI Medium AI 2025-05-22
CVE-2025-48366 GroupOffice's Blind Stored XSS in Phone Number Field Enables Forced Redirect and Unauthorized Actions CWE-79 5.4AI Medium AI 2025-05-22
CVE-2025-25191 Group-Office has a Stored XSS Vulnerability via user's name field CWE-79 5.4 - 2025-03-06
CVE-2024-22418 Stored Cross-site Scripting Vulnerability via Malicious File Names in GroupOffice CWE-79 6.5 Medium 2024-01-18
CVE-2023-46730 Server-Side Request Forgery in groupoffice CWE-918 7.4 High 2023-11-07

All 19 known CVE vulnerabilities affecting groupoffice with full Chinese analysis, references, and POCs where available.