Groupsession maintains a narrowly scoped platform for collaborative communication and session management, with variants including cloud and on-premises deployments, that sits in a position of trust for user authentication and data handling. The vendor's vulnerability profile recurs consistently around application-layer weaknesses: cross-site scripting, open redirect, cross-site request forgery, authorization-bypass conditions tied to user-controlled keys, and exposure of sensitive information to unauthorized actors. These weakness classes reflect the vendor's role as a session and identity intermediary, where improper input handling, weak access controls, and insufficient isolation between user contexts create pathways for lateral movement and account takeover. Defenders should treat Groupsession deployments as sensitive infrastructure, prioritize identity-related patches, and restrict administrative interfaces; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Groupsession over time
Signals from CVEs in this vendor scope (20 CVEs).
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-20874HIGH Incorrect permission assignment for critical resource vulnerability in GroupSession Free edition ver5.1.1 and earlier, GroupSession byCloud ver5.1.1 and earlier, and GroupSession Z | Dec 24, 2021 | 7.5 | 25 | NO | NO |
CVE-2021-20876MEDIUM Path traversal vulnerability in GroupSession Free edition ver5.1.1 and earlier, GroupSession byCloud ver5.1.1 and earlier, and GroupSession ZION ver5.1.1 and earlier allows an atta | Dec 24, 2021 | 6.8 | 23 | NO | NO |
CVE-2021-20875MEDIUM Open redirect vulnerability in GroupSession Free edition ver5.1.1 and earlier, GroupSession byCloud ver5.1.1 and earlier, and GroupSession ZION ver5.1.1 and earlier allows a remote | Dec 24, 2021 | 6.1 | 22 | NO | NO |
CVE-2025-65120MEDIUM Reflected cross-site scripting vulnerability exists in GroupSession Free edition prior to ver5.7.1, GroupSession byCloud prior to ver5.7.1, and GroupSession ZION prior to ver5.7.1. | Dec 12, 2025 | 6.1 | 21 | NO | NO |
CVE-2025-57883MEDIUM Reflected cross-site scripting vulnerability exists in GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior to ver5.3.3, and GroupSession ZION prior to ver5.3.2. | Dec 12, 2025 | 6.1 | 21 | NO | NO |
CVE-2025-54407MEDIUM Stored cross-site scripting vulnerability exists in GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior to ver5.3.3, and GroupSession ZION prior to ver5.3.2. If | Dec 12, 2025 | 6.1 | 21 | NO | NO |
CVE-2021-20789MEDIUM Open redirect vulnerability in GroupSession (GroupSession Free edition from ver2.2.0 to the version prior to ver5.1.0, GroupSession byCloud from ver3.0.3 to the version prior to ve | Jul 30, 2021 | 6.1 | 21 | NO | NO |
CVE-2025-66284MEDIUM Stored cross-site scripting vulnerabilities exist in GroupSession Free edition prior to ver5.7.1, GroupSession byCloud prior to ver5.7.1, and GroupSession ZION prior to ver5.7.1. A | Dec 12, 2025 | 5.4 | 20 | NO | NO |
CVE-2025-62192MEDIUM SQL Injection vulnerability exists in GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior to ver5.3.3, and GroupSession ZION prior to ver5.3.2. If exploited, in | Dec 12, 2025 | 5.4 | 20 | NO | NO |
CVE-2025-61987MEDIUM GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior to ver5.3.3, and GroupSession ZION prior to ver5.3.2. do not validate origins in WebSockets. If a user acces | Dec 12, 2025 | 5.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (20 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Groupsession.
Media articles that mention a CVE ID that affects a product developed by Groupsession — matched by CVE ID, not by vendor name.