Group Office
Vendor:
First CVE: Sep 16, 2010 · Active for 15 years
12
Total CVEs
More Total CVEs than 91% of tracked products
4.0
Avg CVEs / Year
Higher CVE frequency than 85% of tracked products
6.9
Avg CVSS
Higher Avg CVSS than 43% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Group Office over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 16, 2010
15 years ago
Most Recent CVE
Apr 2, 2026
117 days ago
CVE Severity & Scoring
Group Office12 CVEs
58%
33%
8%
All CVEs353,173 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network11 (91.7%)
Unknown1 (8.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (91.7%)
High0 (0.0%)
Unknown1 (8.3%)
User Interaction
None4 (33.3%)
Unknown1 (8.3%)
Required7 (58.3%)
Privileges Required
Low7 (58.3%)
High1 (8.3%)
None3 (25.0%)
Unknown1 (8.3%)
Top CVEs
Signals from CVEs in this product scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-34838CRITICAL Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.156, 25.0.90, and 26.0.12, a vulnerability in the AbstractSettingsCollectio | Apr 2, 2026 | 9.9 | 37 | NO | NO |
CVE-2010-3428HIGH SQL injection vulnerability in modules/notes/json.php in Intermesh Group-Office 3.5.9 allows remote attackers to execute arbitrary SQL commands via the category_id parameter in a c | Sep 16, 2010 | 7.5 | 32 | NO | YES |
CVE-2026-33755HIGH Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.158, 25.0.92, and 26.0.17, an authenticated SQL Injection vulnerability in | Mar 27, 2026 | 8.8 | 29 | NO | NO |
CVE-2026-27947HIGH Group-Office is an enterprise customer relationship management and groupware tool. Versions prior to 26.0.9, 25.0.87, and 6.8.154 have an authenticated Remote Code Execution vulner | Feb 27, 2026 | 8.8 | 29 | NO | NO |
CVE-2026-27832HIGH Group-Office is an enterprise customer relationship management and groupware tool. Versions prior to 26.0.8, 25.0.87, and 6.8.153 have a SQL Injection (SQLi) vulnerability, exploit | Feb 27, 2026 | 8.8 | 27 | NO | NO |
CVE-2026-30237MEDIUM Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.155, 25.0.88, and 26.0.10, there is a reflected XSS vulnerability in the Gr | Mar 6, 2026 | 6.1 | 21 | NO | NO |
CVE-2026-30238MEDIUM Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.155, 25.0.88, and 26.0.10, there is a reflected XSS vulnerability in GroupO | Mar 6, 2026 | 6.1 | 19 | NO | NO |
CVE-2025-48993MEDIUM Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.123 and 25.0.27, a malicious JavaScript payload can be executed via the Loo | Jun 17, 2025 | 6.1 | 18 | NO | NO |
CVE-2025-48369MEDIUM Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.119 and 25.0.20, a persistent Cross-Site Scripting (XSS) vulnerability exis | May 22, 2025 | 5.4 | 18 | NO | NO |
CVE-2025-48368MEDIUM Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.119 and 25.0.20, a DOM-based Cross-Site Scripting (XSS) vulnerability exist | May 22, 2025 | 5.4 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (12 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
8.3% of CVEs· 86th percentile
Social Chatter
Signals from CVEs in this product scope (12 CVEs).
Media Mentions
Signals from CVEs in this product scope (12 CVEs).
Top CNAs Publishing CVEs For Group Office
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3.5.9 | 1 | 7.5 | 1.0% | 0 | 1 |