CVEs affecting projects tracked on Release Alert, from NVD & OSV.
DzzOffice v2.3.7 and before is vulnerable to SQL Injection in explorer/groupmanage.