This page lists publicly disclosed CVE vulnerabilities affecting internet2 grouper (linked via NVD CPE). Each row includes severity scores, summaries, and publication dates to help identify and analyze security issues.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2025-59714 | In Internet2 Grouper 5.17.1 before 5.20.5, group admins who are not Grouper sysadmins can configure loader jobs. | [email protected] | 6.5 | 0.25% | 2025-09-19 | 2025-10-08 |
| CVE-2018-19794 | Cross-site scripting (XSS) vulnerability in UiV2Public.index in Internet2 Grouper 2.2 and 2.3 allows remote attackers to inject arbitrary web script or HTML via the code parameter. | [email protected] | 6.1 | 1.08% | 2018-12-03 | 2024-11-21 |