Groundhogg
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 33 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from August 27, 2019 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →Groundhogg <= 4.8.3 - Unauthenticated Privilege Escalation to Support User Identity Confusion
Groundhogg <= 4.9 - Authenticated (Custom+) Privilege Escalation to 'user' Parameter
WordPress HollerBox plugin <= 2.3.14 - Insecure Direct Object References (IDOR) vulnerability
WordPress Groundhogg plugin <= 4.8.3 - Sensitive Data Exposure vulnerability
WordPress Groundhogg plugin <= 4.8.3 - SQL Injection vulnerability
Groundhogg <= 4.9 - Authenticated (Sales Person+) Privilege Escalation via Contact Identity Rebinding leading to Administrator Account Takeover to 'user_id' Parameter (v3 /contacts) chained with v4 /emails/test
Groundhogg < 4.7.2 - Open Redirect via 'redirect_to' Parameter
Groundhogg < 4.5.13 - Unauthenticated Stored XSS via Web Form Dropdown/Radio Field
Groundhogg <= 4.5.14 - Authenticated (Vendor+) SQL Injection via 'tag_query' Parameter
Groundhogg — CRM, Newsletters, and Marketing Automation <= 4.5.2 - Insecure Direct Object Reference
Monitor Groundhogg in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.