📦 Groupsession

by Groupsession

🔍 What is Groupsession?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2021-20874

HIGH CVSS 7.5 Dec 24, 2021

This vulnerability allows remote unauthenticated attackers to access arbitrary files on GroupSession servers, potentially exposing sensitive information. It affects GroupSession Free edition, GroupSes...

CVE-2025-65120

MEDIUM CVSS 6.1 Dec 12, 2025

A reflected cross-site scripting (XSS) vulnerability in GroupSession collaboration software allows attackers to execute arbitrary JavaScript in users' browsers by tricking them into visiting malicious...

CVE-2025-66284

MEDIUM CVSS 5.4 Dec 12, 2025

Stored cross-site scripting (XSS) vulnerability in GroupSession products allows authenticated users to inject malicious scripts that execute in other users' browsers when they view crafted content. Th...

CVE-2025-64781

MEDIUM CVSS 4.7 Dec 12, 2025

This vulnerability allows attackers to redirect users to arbitrary malicious websites by exploiting a default configuration in GroupSession products. It affects all users of GroupSession Free edition,...

CVE-2025-62192

MEDIUM CVSS 5.4 Dec 12, 2025

An SQL injection vulnerability in GroupSession products allows authenticated users to execute arbitrary SQL commands. This could lead to unauthorized access, modification, or exfiltration of database ...

CVE-2025-54407

MEDIUM CVSS 6.1 Dec 12, 2025

A stored cross-site scripting (XSS) vulnerability in GroupSession products allows attackers to inject malicious scripts that execute in users' browsers when they visit crafted pages or URLs. This affe...

CVE-2025-57883

MEDIUM CVSS 6.1 Dec 12, 2025

A reflected cross-site scripting (XSS) vulnerability in GroupSession collaboration software allows attackers to execute arbitrary JavaScript in users' browsers by tricking them into clicking malicious...

CVE-2025-58576

MEDIUM CVSS 4.3 Dec 12, 2025

A cross-site request forgery (CSRF) vulnerability in GroupSession collaboration software allows attackers to trick authenticated users into performing unintended actions. Users of GroupSession Free ed...

CVE-2025-61950

MEDIUM CVSS 4.3 Dec 12, 2025

This vulnerability allows authenticated users in GroupSession to modify memo fields in Circular notices that should be non-editable due to improper authorization checks. Affected users include all org...

CVE-2025-61987

MEDIUM CVSS 5.3 Dec 12, 2025

This CVE describes a WebSocket origin validation vulnerability in GroupSession products that allows cross-origin WebSocket connections. An attacker can craft a malicious webpage that, when visited by ...

CVE-2025-53523

MEDIUM CVSS 5.4 Dec 12, 2025

This stored cross-site scripting (XSS) vulnerability in GroupSession products allows authenticated attackers to inject malicious scripts into web pages. When other users view the compromised pages, th...