CVE-2025-63406: Group-Office Group Office
High severity, CVSS 8.8. EPSS: 0.7% chance of exploitation in the next 30 days.
An issue in Intermesh BV GroupOffice vulnerable before v.25.0.47 and 6.8.136 allows a remote attacker to execute arbitrary code via the dbToApi() and eval() in the FunctionField.php
Affected products
- Group-Office Group Office: before 6.8.136 (fixed in 6.8.136); from 25.0.1, before 25.0.47 (fixed in 25.0.47)
Published 2025-11-13. Last modified 2026-06-17.