Opengoo is a groupware and collaboration platform with a focused product portfolio that presents a modestly scoped but targeted attack surface. The durable signal centers on path-traversal weaknesses in the core Opengoo product, reflecting input-validation and access-control challenges common to file-handling in web-based collaboration tools. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Opengoo over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
Directory traversal vulnerability in upgrade/index.php in OpenGoo 1.1, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to read arbitrary | Jan 27, 2009 | 2.6 | 19 | NO | YES |
CVE-2009-0806MEDIUM Unspecified vulnerability in OpenGoo before 1.2.1 allows remote authenticated users to modify their own permissions via unknown attack vectors. | Mar 4, 2009 | 6.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Opengoo.
Media articles that mention a CVE ID that affects a product developed by Opengoo — matched by CVE ID, not by vendor name.