CVE-2025-53504: Group-Office Group Office

Medium severity, CVSS 4.8. EPSS: 0.2% chance of exploitation in the next 30 days.

Group-Office versions prior to 6.8.119 and prior to 25.0.20 provided by Intermesh BV contain a cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed in the user's web browser.

Affected products

  • Group-Office Group Office: before 6.8.119 (fixed in 6.8.119); from 25.0.1, before 25.0.20 (fixed in 25.0.20)

Published 2025-08-21. Last modified 2026-06-17.