CVE Tools

Phpgroupware

26 CVEs tracked since 2001. Since May 2001, none of them reached CISA KEV.

Phpgroupware CVEs per month

May 2001 to May 2010. Point at a month, or focus the strip and use the arrow keys.
Phpgroupware CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2001-0510
2001-06null or fewer
2001-07null or fewer
2001-08null or fewer
2001-09null or fewer
2001-10null or fewer
2001-11null or fewer
2001-12null or fewer
2002-01null or fewer
2002-02null or fewer
2002-03null or fewer
2002-04null or fewer
2002-05null or fewer
2002-06null or fewer
2002-07null or fewer
2002-08null or fewer
2002-09null or fewer
2002-10null or fewer
2002-11null or fewer
2002-12null or fewer
2003-01null or fewer
2003-02null or fewer
2003-03null or fewer
2003-0410
2003-05null or fewer
2003-06null or fewer
2003-0720
2003-0810
2003-09null or fewer
2003-10null or fewer
2003-11null or fewer
2003-12null or fewer
2004-0110
2004-02null or fewer
2004-03null or fewer
2004-04null or fewer
2004-05null or fewer
2004-06null or fewer
2004-07null or fewer
2004-08null or fewer
2004-0920
2004-10null or fewer
2004-11null or fewer
2004-12null or fewer
2005-01null or fewer
2005-0230
2005-03null or fewer
2005-04null or fewer
2005-05null or fewer
2005-06null or fewer
2005-07null or fewer
2005-0830
2005-09null or fewer
2005-10null or fewer
2005-1170
2005-12null or fewer
2006-01null or fewer
2006-02null or fewer
2006-03null or fewer
2006-04null or fewer
2006-05null or fewer
2006-06null or fewer
2006-07null or fewer
2006-08null or fewer
2006-09null or fewer
2006-10null or fewer
2006-11null or fewer
2006-12null or fewer
2007-01null or fewer
2007-02null or fewer
2007-03null or fewer
2007-04null or fewer
2007-05null or fewer
2007-06null or fewer
2007-07null or fewer
2007-08null or fewer
2007-09null or fewer
2007-10null or fewer
2007-11null or fewer
2007-12null or fewer
2008-01null or fewer
2008-02null or fewer
2008-03null or fewer
2008-04null or fewer
2008-05null or fewer
2008-06null or fewer
2008-07null or fewer
2008-08null or fewer
2008-09null or fewer
2008-10null or fewer
2008-11null or fewer
2008-12null or fewer
2009-01null or fewer
2009-02null or fewer
2009-03null or fewer
2009-04null or fewer
2009-05null or fewer
2009-06null or fewer
2009-07null or fewer
2009-08null or fewer
2009-09null or fewer
2009-10null or fewer
2009-11null or fewer
2009-1230
2010-01null or fewer
2010-02null or fewer
2010-03null or fewer
2010-04null or fewer
2010-0520

Products

The products that kept showing up in Phpgroupware's monthly top three, with their CVEs summed over those months.

  1. Phpgroupware2611 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Phpgroupware.

  1. CVE-2010-0403Directory traversal vulnerability in about.php in phpGroupWare (phpgw) before 0.9.16.016 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the app parameter.6.8
  2. CVE-2010-0404Multiple SQL injection vulnerabilities in phpGroupWare (phpgw) before 0.9.16.016 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to (1) class.sessions_db.inc.php...7.5
  3. CVE-2009-4416Cross-site scripting (XSS) vulnerability in login.php in phpGroupWare 0.9.16.12, and possibly other versions before 0.9.16.014, allows remote attackers to inject arbitrary web script or HTML via an...4.3
  4. CVE-2009-4415Multiple directory traversal vulnerabilities in phpGroupWare 0.9.16.12, and possibly other versions before 0.9.16.014, allow remote attackers to (1) read arbitrary files via the csvfile parameter t...7.5
  5. CVE-2009-4414SQL injection vulnerability in phpgwapi /inc/class.auth_sql.inc.php in phpGroupWare 0.9.16.12, and possibly other versions before 0.9.16.014, when magic_quotes_gpc is disabled, allows remote attack...6.8
  6. CVE-2006-4458Directory traversal vulnerability in calendar/inc/class.holidaycalc.inc.php in phpGroupWare 0.9.16.010 and earlier allows remote attackers to include arbitrary local files via a .. (dot dot) sequen...6.4
  7. CVE-2004-2575phpGroupWare 0.9.14.005 and earlier allow remote attackers to obtain sensitive information via a direct request to (1) hook_admin.inc.php, (2) hook_home.inc.php, (3) class.holidaycalc.inc.php, and ...5.0
  8. CVE-2004-2573PHP remote file inclusion vulnerability in tables_update.inc.php in phpGroupWare 0.9.14.005 and earlier allows remote attackers to execute arbitrary PHP code via an external URL in the appdir param...7.5
  9. CVE-2004-2577The acl_check function in phpGroupWare 0.9.16RC2 always returns True, even when mkdir does not behave as expected, which could allow remote attackers to obtain sensitive information via WebDAV from...5.0
  10. CVE-2004-2578phpGroupWare before 0.9.16.002 transmits the (1) header admin and (2) setup passwords in plaintext via cookies, which allows remote attackers to sniff passwords.5.0
  11. CVE-2004-2576class.vfs_dav.inc.php in phpGroupWare 0.9.16.000 does not create .htaccess files to enable authorization checks for access to users' home-directory files, which allows remote attackers to obtain se...5.0
  12. CVE-2004-2574Cross-site scripting (XSS) vulnerability in index.php in phpGroupWare 0.9.14.005 and earlier allows remote attackers to inject arbitrary web script or HTML via the date parameter in a calendar.uica...4.3
  13. CVE-2005-3347Multiple directory traversal vulnerabilities in index.php in phpSysInfo 2.4 and earlier, as used in phpgroupware 0.9.16 and earlier, and egrouwpware before 1.0.0.009, allow remote attackers to incl...6.8
  14. CVE-2005-2761Cross-site scripting (XSS) vulnerability in phpGroupWare 0.9.16.000 allows administrators to inject arbitrary web script or HTML by modifying the main screen message.4.3
  15. CVE-2004-2406Unknown "overflow" in the phpgw_config table for phpGroupWare before 0.9.14.002 has unknown attack vectors and impact.10.0

The record

Peak rank
#14 in Nov 2005
Busiest month shown
Nov 2005, 7 CVEs
Months with a KEV entry
0 since May 2001
Monthly snapshots
11 since 2001
Phpgroupware's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store