Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Egroupware

First CVE: Dec 31, 2004Active for: 22 yearsTotal CVEs: 25
38.5
VTI Score
Medium

Egroupware is a modestly represented groupware and collaboration platform that, despite a narrow product line concentrated around its core suite and enterprise variant, appears among the more prominent vendors in the vulnerability landscape. The vendor's disclosures recur across input-handling and code-generation weaknesses, including cross-site scripting, SQL injection, and code injection vulnerabilities that are typical of web-facing application frameworks, and frequently acquire public exploit code. The exposure pattern reflects the complexity of managing user input across a feature-rich collaboration platform that integrates email, calendar, contacts, and document management, presenting a multi-faceted web attack surface. Defenders should apply input-validation and output-encoding scrutiny when tracking Egroupware releases and treat internet-exposed instances as requiring prompt patching; current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
25
Total CVEs
More Total CVEs than 97% of tracked vendors
1.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
6.5
Avg CVSS Score
Higher Avg CVSS Score than 39% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Egroupware over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2004
21 years ago
Most Recent CVE
Jan 28, 2026
179 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (25 CVEs).

25 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2010-3313HIGH
phpgwapi/js/fckeditor/editor/dialog/fck_spellerpages/spellerpages/serverscripts/spellchecker.php in EGroupware 1.4.001+.002; 1.6.001+.002 and possibly other versions before 1.6.003
Sep 22, 20107.538NOYES
CVE-2005-1203HIGH
Multiple SQL injection vulnerabilities in index.php in eGroupware before 1.0.0.007 allow remote attackers to execute arbitrary SQL commands via the (1) filter or (2) cats_app param
May 2, 20057.529NOYES
CVE-2024-40614CRITICAL
EGroupware before 23.1.20240624 mishandles an ORDER BY clause. This leads to json.php?menuaction=EGroupware\Api\Etemplate\Widget\Nextmatch::ajax_get_rows sort.id SQL injection by a
Jul 7, 20249.828NONO
CVE-2007-3155HIGH
Unspecified vulnerability in eGroupWare before 1.2.107-2 has unknown impact and attack vectors related to ADOdb. NOTE: due to lack of details from the vendor, it is uncertain whet
Jun 11, 200710.027NONO
CVE-2005-1202MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in eGroupware before 1.0.0.007 allow remote attackers to inject arbitrary web script or HTML via the (1) ab_id, (2) page, (3) ty
May 2, 20056.827NOYES
CVE-2014-2987MEDIUM
Multiple cross-site request forgery (CSRF) vulnerabilities in EGroupware Enterprise Line (EPL) before 1.1.20140505, EGroupware Community Edition before 1.8.007.20140506, and EGroup
Oct 26, 20146.826NOYES
CVE-2007-3154HIGH
Unspecified vulnerability in Walter Zorn wz_tooltip.js (aka wz_tooltips) before 4.01, as used by eGroupWare before 1.2.107-2 and other packages, has unknown impact and remote attac
Jun 11, 200710.026NONO
CVE-2026-22243HIGH
EGroupware is a Web based groupware server written in PHP. A SQL Injection vulnerability exists in the core components of EGroupware prior to versions 23.1.20260113 and 26.0.202601
Jan 28, 20268.825NONO
CVE-2014-2027HIGH
eGroupware before 1.8.006.20140217 allows remote attackers to conduct PHP object injection attacks, delete arbitrary files, and possibly execute arbitrary code via the (1) addr_fie
Mar 31, 20157.525NONO
CVE-2010-3314MEDIUM
Cross-site scripting (XSS) vulnerability in login.php in EGroupware 1.4.001+.002; 1.6.001+.002 and possibly other versions before 1.6.003; and EPL 9.1 before 9.1.20100309 and 9.2 b
Sep 22, 20104.325NOYES
View all 25 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products25 CVEs
56%
36%
Severity distribution among all CVEs352,713 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network6 (24.0%)
Unknown19 (76.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (24.0%)
High0 (0.0%)
Unknown19 (76.0%)
User Interaction
None4 (16.0%)
Unknown19 (76.0%)
Required2 (8.0%)
Privileges Required
Low1 (4.0%)
High1 (4.0%)
None4 (16.0%)
Unknown19 (76.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (25 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
6 CVEs
24.0% of CVEs· 78th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Egroupware.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Egroupware — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Egroupware's Products

View all 3 CNAs →

Top CWEs