Intermesh maintains Group Office, a web-based collaboration and productivity platform that serves a modest but distributed user base, and its vulnerability footprint centers on application-layer input-handling and data-processing weaknesses. The recurring exposure reflects typical risks in web applications that handle user-supplied content and execute dynamic queries: cross-site scripting variants, SQL injection, deserialization flaws, and argument injection, alongside a moderate share that reach serious severity and acquire public exploit code. Defenders managing deployments of this platform should prioritize input-validation and query-parameterization practices; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Intermesh over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-34838CRITICAL Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.156, 25.0.90, and 26.0.12, a vulnerability in the AbstractSettingsCollectio | Apr 2, 2026 | 9.9 | 34 | NO | NO |
CVE-2010-3428HIGH SQL injection vulnerability in modules/notes/json.php in Intermesh Group-Office 3.5.9 allows remote attackers to execute arbitrary SQL commands via the category_id parameter in a c | Sep 16, 2010 | 7.5 | 32 | NO | YES |
CVE-2026-33755HIGH Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.158, 25.0.92, and 26.0.17, an authenticated SQL Injection vulnerability in | Mar 27, 2026 | 8.8 | 29 | NO | NO |
CVE-2026-27947HIGH Group-Office is an enterprise customer relationship management and groupware tool. Versions prior to 26.0.9, 25.0.87, and 6.8.154 have an authenticated Remote Code Execution vulner | Feb 27, 2026 | 8.8 | 29 | NO | NO |
CVE-2026-27832HIGH Group-Office is an enterprise customer relationship management and groupware tool. Versions prior to 26.0.8, 25.0.87, and 6.8.153 have a SQL Injection (SQLi) vulnerability, exploit | Feb 27, 2026 | 8.8 | 27 | NO | NO |
CVE-2026-30237MEDIUM Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.155, 25.0.88, and 26.0.10, there is a reflected XSS vulnerability in the Gr | Mar 6, 2026 | 6.1 | 21 | NO | NO |
CVE-2026-30238MEDIUM Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.155, 25.0.88, and 26.0.10, there is a reflected XSS vulnerability in GroupO | Mar 6, 2026 | 6.1 | 19 | NO | NO |
CVE-2025-48993MEDIUM Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.123 and 25.0.27, a malicious JavaScript payload can be executed via the Loo | Jun 17, 2025 | 6.1 | 18 | NO | NO |
CVE-2025-48369MEDIUM Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.119 and 25.0.20, a persistent Cross-Site Scripting (XSS) vulnerability exis | May 22, 2025 | 5.4 | 18 | NO | NO |
CVE-2025-48368MEDIUM Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.119 and 25.0.20, a DOM-based Cross-Site Scripting (XSS) vulnerability exist | May 22, 2025 | 5.4 | 18 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Intermesh.
Media articles that mention a CVE ID that affects a product developed by Intermesh — matched by CVE ID, not by vendor name.