Intermesh records
12 published records for vendor intermesh.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')7
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
- CWE-502 Deserialization of Untrusted Data1
- CWE-88 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
12 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2026-34838Proof of concept | Group-Office: Authenticated Remote Code Execution via PHP Insecure Deserialization in `AbstractSettingsCollection`intermesh · group-office · CWE-502 | Critical9.9 | — | 1.0% | Apr 2, 2026 |
37Monitor | CVE-2026-27947No exploit | Group-Office Vulnerable to Remote Code Execution (RCE)intermesh · group-office · CWE-88 | Critical9.4 | — | 1.0% | Feb 27, 2026 |
35Monitor | CVE-2026-33755No exploit | Authenticated SQL Injection in Contact/query addressBookIds filterintermesh · group-office · CWE-89 | High8.8 | — | 0.5% | Mar 27, 2026 |
30Monitor | CVE-2010-3428Proof of concept | SQL injection vulnerability in modules/notes/json.php in Intermesh Group-Office 3.5.9 allows remote attackers to execute arbitrary SQL commaintermesh · group-office · CWE-89 | High7.5 | — | 1.0% | Sep 16, 2010 |
28Monitor | CVE-2026-27832No exploit | Group-Office Has Authenticated SQL Injection in advancedQueryData.comparatorintermesh · group-office · CWE-89 | High7.1 | — | 0.5% | Feb 27, 2026 |
27Monitor | CVE-2025-48366No exploit | GroupOffice's Blind Stored XSS in Phone Number Field Enables Forced Redirect and Unauthorized Actionsintermesh · group-office · CWE-79 | Medium6.9 | — | 0.3% | May 22, 2025 |
23Monitor | CVE-2025-48368No exploit | GroupOffice's DOM-Based XSS in all Date Input Fields Allows Arbitrary JavaScript Executionintermesh · group-office · CWE-79 | Medium5.8 | — | 0.3% | May 22, 2025 |
21Monitor | CVE-2025-48369No exploit | GroupOffice vulnerable to Stored XSS in Tasks Comment Sectionintermesh · group-office · CWE-79 | Medium5.3 | — | 0.3% | May 22, 2025 |
21Monitor | CVE-2025-48993No exploit | Group-Office vulnerable to reflected XSS via Look and Feel Formatting inputintermesh · group-office · CWE-79 | Medium5.3 | — | 0.3% | Jun 16, 2025 |
20Monitor | CVE-2026-30238No exploit | Group-Office: Reflected XSS in JavaScript contextintermesh · group-office · CWE-79 | Medium5.1 | — | 0.3% | Mar 6, 2026 |
20Monitor | CVE-2025-48992No exploit | Group-Office vulnerable to blind XSSintermesh · group-office · CWE-79 | Medium5.2 | — | 0.3% | Jun 16, 2025 |
8Monitor | CVE-2026-30237No exploit | Group-Office: Self XSS in GroupOffice Installer License Page (install/license.php)intermesh · group-office · CWE-79 | Low2.1 | — | 0.3% | Mar 6, 2026 |
- CVE-2026-3483839Monitor
Group-Office: Authenticated Remote Code Execution via PHP Insecure Deserialization in `AbstractSettingsCollection`
CriticalCVSS 9.9Proof of conceptEPSS 1%intermesh · group-officeApr 2, 2026
- CVE-2026-2794737Monitor
Group-Office Vulnerable to Remote Code Execution (RCE)
CriticalCVSS 9.4No exploitEPSS 1%intermesh · group-officeFeb 27, 2026
- CVE-2026-3375535Monitor
Authenticated SQL Injection in Contact/query addressBookIds filter
HighCVSS 8.8No exploitEPSS 0%intermesh · group-officeMar 27, 2026
- CVE-2010-342830Monitor
SQL injection vulnerability in modules/notes/json.php in Intermesh Group-Office 3.5.9 allows remote attackers to execute arbitrary SQL comma
HighCVSS 7.5Proof of conceptEPSS 1%intermesh · group-officeSep 16, 2010
- CVE-2026-2783228Monitor
Group-Office Has Authenticated SQL Injection in advancedQueryData.comparator
HighCVSS 7.1No exploitEPSS 0%intermesh · group-officeFeb 27, 2026
- CVE-2025-4836627Monitor
GroupOffice's Blind Stored XSS in Phone Number Field Enables Forced Redirect and Unauthorized Actions
MediumCVSS 6.9No exploitEPSS 0%intermesh · group-officeMay 22, 2025
- CVE-2025-4836823Monitor
GroupOffice's DOM-Based XSS in all Date Input Fields Allows Arbitrary JavaScript Execution
MediumCVSS 5.8No exploitEPSS 0%intermesh · group-officeMay 22, 2025
- CVE-2025-4836921Monitor
GroupOffice vulnerable to Stored XSS in Tasks Comment Section
MediumCVSS 5.3No exploitEPSS 0%intermesh · group-officeMay 22, 2025
- CVE-2025-4899321Monitor
Group-Office vulnerable to reflected XSS via Look and Feel Formatting input
MediumCVSS 5.3No exploitEPSS 0%intermesh · group-officeJun 16, 2025
- CVE-2026-3023820Monitor
Group-Office: Reflected XSS in JavaScript context
MediumCVSS 5.1No exploitEPSS 0%intermesh · group-officeMar 6, 2026
- CVE-2025-4899220Monitor
Group-Office vulnerable to blind XSS
MediumCVSS 5.2No exploitEPSS 0%intermesh · group-officeJun 16, 2025
- CVE-2026-302378Monitor
Group-Office: Self XSS in GroupOffice Installer License Page (install/license.php)
LowCVSS 2.1No exploitEPSS 0%intermesh · group-officeMar 6, 2026