Groundhogg develops a focused suite of marketing automation and customer relationship management tools, including its core platform and related offerings like Hollerbox, that serve small-to-medium businesses and WordPress-based deployments. The vulnerability profile concentrates on application-layer input-handling and access-control weaknesses, including cross-site scripting, SQL injection, cross-site request forgery, code injection, and missing authorization checks, which reflect the challenges of securing web-based SaaS and plugin architectures. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Groundhogg over time
Signals from CVEs in this vendor scope (23 CVEs).
23 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-57389HIGH Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Adrian Tobey Groundhogg groundhogg allows Path Traversal.This issue affects Groundho | Jul 13, 2026 | 8.6 | 36 | NO | NO |
CVE-2026-57667HIGH Sales Representative SQL Injection in Groundhogg <= 4.5 versions. | Jun 26, 2026 | 8.5 | 36 | NO | NO |
CVE-2026-40727HIGH Sales Representative Arbitrary File Deletion in Groundhogg <= 4.4 versions. | Jun 15, 2026 | 7.7 | 30 | NO | NO |
CVE-2019-15647HIGH The groundhogg plugin before 1.3.5 for WordPress has wp-admin/admin-ajax.php?action=bulk_action_listener remote code execution. | Aug 27, 2019 | 8.8 | 28 | NO | NO |
CVE-2023-2736HIGH The Groundhogg plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.7.9.8. This is due to missing nonce validation in the 'ajax_edit | May 20, 2023 | 8.0 | 25 | NO | NO |
CVE-2026-40793MEDIUM Subscriber Broken Access Control in Groundhogg < 4.4.1 versions. | Jun 15, 2026 | 6.5 | 24 | NO | NO |
CVE-2025-48300CRITICAL Unrestricted Upload of File with Dangerous Type vulnerability in Adrian Tobey Groundhogg groundhogg allows Upload a Web Shell to a Web Server.This issue affects Groundhogg: from n/ | Jul 16, 2025 | 9.1 | 24 | NO | NO |
CVE-2023-34178HIGH Cross-Site Request Forgery (CSRF) vulnerability in Groundhogg Inc. Groundhogg plugin <= 2.7.11 versions. | Nov 9, 2023 | 8.8 | 24 | NO | NO |
CVE-2025-54053MEDIUM Deserialization of Untrusted Data vulnerability in Adrian Tobey Groundhogg groundhogg allows Object Injection.This issue affects Groundhogg: from n/a through <= 4.2.2. | Aug 20, 2025 | 6.6 | 23 | NO | NO |
CVE-2023-1425HIGH The WordPress CRM, Email & Marketing Automation for WordPress | Award Winner — Groundhogg WordPress plugin before 2.7.9.4 does not properly sanitise and escape a parameter before u | Apr 10, 2023 | 7.2 | 23 | NO | NO |
Signals from CVEs in this vendor scope (23 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Groundhogg.
Media articles that mention a CVE ID that affects a product developed by Groundhogg — matched by CVE ID, not by vendor name.