Egroupware is a modestly represented groupware and collaboration platform that, despite a narrow product line concentrated around its core suite and enterprise variant, appears among the more prominent vendors in the vulnerability landscape. The vendor's disclosures recur across input-handling and code-generation weaknesses, including cross-site scripting, SQL injection, and code injection vulnerabilities that are typical of web-facing application frameworks, and frequently acquire public exploit code. The exposure pattern reflects the complexity of managing user input across a feature-rich collaboration platform that integrates email, calendar, contacts, and document management, presenting a multi-faceted web attack surface. Defenders should apply input-validation and output-encoding scrutiny when tracking Egroupware releases and treat internet-exposed instances as requiring prompt patching; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Egroupware over time
Signals from CVEs in this vendor scope (25 CVEs).
25 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-3313HIGH phpgwapi/js/fckeditor/editor/dialog/fck_spellerpages/spellerpages/serverscripts/spellchecker.php in EGroupware 1.4.001+.002; 1.6.001+.002 and possibly other versions before 1.6.003 | Sep 22, 2010 | 7.5 | 38 | NO | YES |
CVE-2005-1203HIGH Multiple SQL injection vulnerabilities in index.php in eGroupware before 1.0.0.007 allow remote attackers to execute arbitrary SQL commands via the (1) filter or (2) cats_app param | May 2, 2005 | 7.5 | 29 | NO | YES |
CVE-2024-40614CRITICAL EGroupware before 23.1.20240624 mishandles an ORDER BY clause. This leads to json.php?menuaction=EGroupware\Api\Etemplate\Widget\Nextmatch::ajax_get_rows sort.id SQL injection by a | Jul 7, 2024 | 9.8 | 28 | NO | NO |
CVE-2007-3155HIGH Unspecified vulnerability in eGroupWare before 1.2.107-2 has unknown impact and attack vectors related to ADOdb. NOTE: due to lack of details from the vendor, it is uncertain whet | Jun 11, 2007 | 10.0 | 27 | NO | NO |
CVE-2005-1202MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in eGroupware before 1.0.0.007 allow remote attackers to inject arbitrary web script or HTML via the (1) ab_id, (2) page, (3) ty | May 2, 2005 | 6.8 | 27 | NO | YES |
CVE-2014-2987MEDIUM Multiple cross-site request forgery (CSRF) vulnerabilities in EGroupware Enterprise Line (EPL) before 1.1.20140505, EGroupware Community Edition before 1.8.007.20140506, and EGroup | Oct 26, 2014 | 6.8 | 26 | NO | YES |
CVE-2007-3154HIGH Unspecified vulnerability in Walter Zorn wz_tooltip.js (aka wz_tooltips) before 4.01, as used by eGroupWare before 1.2.107-2 and other packages, has unknown impact and remote attac | Jun 11, 2007 | 10.0 | 26 | NO | NO |
CVE-2026-22243HIGH EGroupware is a Web based groupware server written in PHP. A SQL Injection vulnerability exists in the core components of EGroupware prior to versions 23.1.20260113 and 26.0.202601 | Jan 28, 2026 | 8.8 | 25 | NO | NO |
CVE-2014-2027HIGH eGroupware before 1.8.006.20140217 allows remote attackers to conduct PHP object injection attacks, delete arbitrary files, and possibly execute arbitrary code via the (1) addr_fie | Mar 31, 2015 | 7.5 | 25 | NO | NO |
CVE-2010-3314MEDIUM Cross-site scripting (XSS) vulnerability in login.php in EGroupware 1.4.001+.002; 1.6.001+.002 and possibly other versions before 1.6.003; and EPL 9.1 before 9.1.20100309 and 9.2 b | Sep 22, 2010 | 4.3 | 25 | NO | YES |
Signals from CVEs in this vendor scope (25 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Egroupware.
Media articles that mention a CVE ID that affects a product developed by Egroupware — matched by CVE ID, not by vendor name.