Groundhogg — CRM, Newsletters, and Marketing Automation
groundhoggVulnerabilities:
22
Last Updated:
March 6, 2026
Active Installs:
2000
Published
Title
Fixed in
CVSS
Published
2025-11-20
Fixed in
CVSS
4.9 (medium)
Published
2025-10-31
Fixed in
CVSS
6.4 (medium)
Published
2025-08-05
Fixed in
CVSS
7.5 (high)
Published
2025-07-04
Fixed in
CVSS
8.8 (high)
Published
2025-05-08
Fixed in
CVSS
7.2 (high)
Published
2025-03-31
Title
Groundhogg < 4.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via label Parameter
Fixed in
CVSS
5.5 (medium)
Published
2025-01-13
Title
Groundhogg < 3.7.3.6 - Authenticated (Author+) Arbitrary File Upload via gh_big_file_upload Function
Fixed in
CVSS
8.8 (high)
Published
2025-01-03
Fixed in
CVSS
6.1 (medium)
Published
2024-06-27
Fixed in
CVSS
6.1 (medium)
Published
2024-06-21
Fixed in
CVSS
4.3 (medium)
Published
2023-10-25
Fixed in
CVSS
3.5 (low)
Published
2023-05-30
Fixed in
CVSS
4.1 (medium)
Published
2023-05-30
Fixed in
CVSS
4.3 (medium)
Published
2023-05-19
Fixed in
CVSS
4.9 (medium)
Published
2023-05-19
Fixed in
CVSS
7.5 (high)
Published
2023-05-19
Fixed in
CVSS
5.4 (medium)
Published
2023-05-19
Fixed in
CVSS
4.3 (medium)
Published
2023-05-19
Fixed in
CVSS
5.4 (medium)
Published
2023-03-20
Fixed in
CVSS
6.8 (medium)
Published
2019-10-23
Fixed in
CVSS
n/a
Published
2019-10-23
Fixed in
CVSS
n/a
Published
2019-04-08
Fixed in
CVSS
8.8 (high)