Egroupware

    Dashboard / Vendors

    Products: 2
    Vulnerabilities: 27
    Known Exploited: 0
    3
    Critical Level Threats
    6
    High Level Threats
    15
    Medium Level Threats
    1
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-40187

    Authenticated RCE via Malicious eTemplate Upload in EGroupware

    Last Modified: Jul 20, 2026
    Published: Jul 20, 2026

    CVE-2026-27823

    Remote Code Execution Vulnerability in EGroupware

    Last Modified: Jul 21, 2026
    Published: Jul 20, 2026

    CVE-2026-22243

    EGroupware has SQL Injection in Nextmatch Filter Processing

    Last Modified: Apr 18, 2026
    Published: Jan 28, 2026

    CVE-2023-38329

    An issue was discovered in eGroupWare 17.1.20190111. A cross-site scripting Reflected (XSS) vulnerability exists in calendar/freebusy.php, which allows unauthenticated remote attackers to inject arbitrary web script or HTML into the "user" HTTP/GET parameter, which reflects its input without sanitization.

    Last Modified: Sep 11, 2025
    Published: Jul 11, 2025

    CVE-2023-38327

    An issue was discovered in eGroupWare 17.1.20190111. A User Enumeration vulnerability exists under calendar/freebusy.php, which allows unauthenticated remote attackers to enumerate the users of web applications based on server response.

    Last Modified: Sep 11, 2025
    Published: Jul 11, 2025
    Items Per Page