Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Phpgroupware

First CVE: Feb 16, 2001Active for: 25 yearsTotal CVEs: 27
46.8
VTI Score
High

Phpgroupware is a web-based groupware and collaboration platform whose vulnerability profile, though concentrated in a single product line, has attracted a sustained pattern of public exploit development. The recurring weakness classes—path traversal, SQL injection, and cross-site scripting—reflect the application's role as a server-side web service handling user input and file access, and these classes have historically been attractive targets for weaponization and automated tooling. Defenders deploying or maintaining instances of Phpgroupware should treat input validation, file-path handling, and output encoding as critical hardening points and monitor for exploit availability given the durable tendency of this product's vulnerabilities to acquire public proof-of-concept code. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
27
Total CVEs
More Total CVEs than 97% of tracked vendors
3.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
6.7
Avg CVSS Score
Higher Avg CVSS Score than 43% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Phpgroupware over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 16, 2001
25 years ago
Most Recent CVE
May 19, 2010
5,910 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (27 CVEs).

27 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2004-1383HIGH
Multiple SQL injection vulnerabilities in phpGroupWare 0.9.16.003 and earlier allow remote attackers to execute arbitrary SQL statements via the (1) order, (2) project_id, (3) pro_
Dec 31, 20047.535NOYES
CVE-2004-2573HIGH
PHP remote file inclusion vulnerability in tables_update.inc.php in phpGroupWare 0.9.14.005 and earlier allows remote attackers to execute arbitrary PHP code via an external URL in
Dec 31, 20047.535NOYES
CVE-2001-0043HIGH
phpGroupWare before 0.9.7 allows remote attackers to execute arbitrary PHP commands by specifying a malicious include file in the phpgw_info parameter of the phpgw.inc.php program.
Feb 16, 200110.031NONO
CVE-2002-0536HIGH
PHPGroupware 0.9.12 and earlier, when running with the magic_quotes_gpc feature disabled, allows remote attackers to compromise the database via a SQL injection attack.
Jul 3, 20027.528NOYES
CVE-2006-4458MEDIUM
Directory traversal vulnerability in calendar/inc/class.holidaycalc.inc.php in phpGroupWare 0.9.16.010 and earlier allows remote attackers to include arbitrary local files via a ..
Aug 31, 20066.426NOYES
CVE-2004-1385MEDIUM
phpGroupWare 0.9.16.003 and earlier allows remote attackers to gain sensitive information via (1) unexpected characters in the session ID such as shell metacharacters, (2) an inval
Dec 31, 20045.025NOYES
CVE-2004-2407HIGH
Unknown vulnerability in phpGroupWare before 0.9.14.002 has unknown attack vectors and impact, related to a "security hole" in the Setup/Config functionality.
Dec 31, 200410.025NONO
CVE-2004-0016HIGH
The calendar module for phpgroupware 0.9.14 does not enforce the "save extension" feature for holiday files, which allows remote attackers to create and execute PHP files.
Feb 3, 20047.525NONO
CVE-2003-0599HIGH
Unknown vulnerability in the Virtual File System (VFS) capability for phpGroupWare 0.9.16preRC and versions before 0.9.14.004 with unknown implications, related to the VFS path bei
Aug 27, 200310.025NONO
CVE-2004-2406HIGH
Unknown "overflow" in the phpgw_config table for phpGroupWare before 0.9.14.002 has unknown attack vectors and impact.
Dec 31, 200410.024NONO
View all 27 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products27 CVEs
56%
44%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown27 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown27 (100.0%)
User Interaction
None0 (0.0%)
Unknown27 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown27 (100.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (27 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
7 CVEs
25.9% of CVEs· 78th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Phpgroupware.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Phpgroupware — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Phpgroupware's Products

View all 2 CNAs →

Top CWEs