Phpgroupware is a web-based groupware and collaboration platform whose vulnerability profile, though concentrated in a single product line, has attracted a sustained pattern of public exploit development. The recurring weakness classes—path traversal, SQL injection, and cross-site scripting—reflect the application's role as a server-side web service handling user input and file access, and these classes have historically been attractive targets for weaponization and automated tooling. Defenders deploying or maintaining instances of Phpgroupware should treat input validation, file-path handling, and output encoding as critical hardening points and monitor for exploit availability given the durable tendency of this product's vulnerabilities to acquire public proof-of-concept code. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Phpgroupware over time
Signals from CVEs in this vendor scope (27 CVEs).
27 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2004-1383HIGH Multiple SQL injection vulnerabilities in phpGroupWare 0.9.16.003 and earlier allow remote attackers to execute arbitrary SQL statements via the (1) order, (2) project_id, (3) pro_ | Dec 31, 2004 | 7.5 | 35 | NO | YES |
CVE-2004-2573HIGH PHP remote file inclusion vulnerability in tables_update.inc.php in phpGroupWare 0.9.14.005 and earlier allows remote attackers to execute arbitrary PHP code via an external URL in | Dec 31, 2004 | 7.5 | 35 | NO | YES |
CVE-2001-0043HIGH phpGroupWare before 0.9.7 allows remote attackers to execute arbitrary PHP commands by specifying a malicious include file in the phpgw_info parameter of the phpgw.inc.php program. | Feb 16, 2001 | 10.0 | 31 | NO | NO |
CVE-2002-0536HIGH PHPGroupware 0.9.12 and earlier, when running with the magic_quotes_gpc feature disabled, allows remote attackers to compromise the database via a SQL injection attack. | Jul 3, 2002 | 7.5 | 28 | NO | YES |
CVE-2006-4458MEDIUM Directory traversal vulnerability in calendar/inc/class.holidaycalc.inc.php in phpGroupWare 0.9.16.010 and earlier allows remote attackers to include arbitrary local files via a .. | Aug 31, 2006 | 6.4 | 26 | NO | YES |
CVE-2004-1385MEDIUM phpGroupWare 0.9.16.003 and earlier allows remote attackers to gain sensitive information via (1) unexpected characters in the session ID such as shell metacharacters, (2) an inval | Dec 31, 2004 | 5.0 | 25 | NO | YES |
CVE-2004-2407HIGH Unknown vulnerability in phpGroupWare before 0.9.14.002 has unknown attack vectors and impact, related to a "security hole" in the Setup/Config functionality. | Dec 31, 2004 | 10.0 | 25 | NO | NO |
CVE-2004-0016HIGH The calendar module for phpgroupware 0.9.14 does not enforce the "save extension" feature for holiday files, which allows remote attackers to create and execute PHP files. | Feb 3, 2004 | 7.5 | 25 | NO | NO |
CVE-2003-0599HIGH Unknown vulnerability in the Virtual File System (VFS) capability for phpGroupWare 0.9.16preRC and versions before 0.9.14.004 with unknown implications, related to the VFS path bei | Aug 27, 2003 | 10.0 | 25 | NO | NO |
CVE-2004-2406HIGH Unknown "overflow" in the phpgw_config table for phpGroupWare before 0.9.14.002 has unknown attack vectors and impact. | Dec 31, 2004 | 10.0 | 24 | NO | NO |
Signals from CVEs in this vendor scope (27 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Phpgroupware.
Media articles that mention a CVE ID that affects a product developed by Phpgroupware — matched by CVE ID, not by vendor name.