CVE-2026-23887 is a Stored Cross-Site Scripting (XSS) vulnerability affecting Group-Office versions 6.8.148 and below, and 25.0.1 through 25.0.79. The flaw arises from the application storing unsanitized filenames in its database, allowing specially crafted filenames to execute malicious scripts when viewed. Rated 5.4 MEDIUM, this vulnerability requires user interaction (UI:R) and authenticated access (PR:L) to trigger, with potential impacts including interference with user sessions or unintended browser actions. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.8.149CPE matchmatch criteria | cpe:2.3:a:group-office:group_office:*:*:*:*:*:*:*:* | ||
>= 25.0.1, < 25.0.80CPE matchmatch criteria | cpe:2.3:a:group-office:group_office:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.