Vulnerabilities > Egroupware

DATE CVE VULNERABILITY TITLE RISK
2024-07-07 CVE-2024-40614 Unspecified vulnerability in Egroupware
EGroupware before 23.1.20240624 mishandles an ORDER BY clause.
network
low complexity
egroupware
critical
9.8
2023-10-26 CVE-2023-38328 Insufficiently Protected Credentials vulnerability in Egroupware 17.1.20190111
An issue was discovered in eGroupWare 17.1.20190111.
network
low complexity
egroupware CWE-522
4.9
2017-09-30 CVE-2017-14920 Cross-site Scripting vulnerability in Egroupware
Stored XSS vulnerability in eGroupware Community Edition before 16.1.20170922 allows an unauthenticated remote attacker to inject JavaScript via the User-Agent HTTP header, which is mishandled during rendering by the application administrator.
network
low complexity
egroupware CWE-79
6.1