Skip to main content

Vendor/product archive

weseek / growi CVEs

Beta · best-effort

43 CVEs tagged to weseek / growi1 Critical, 9 High, 32 Medium, 1 Low, 0 Unrated.

CVE-2025-54806

Published Oct 23, 2025

GROWI v4.2.7 and earlier contains a cross-site scripting vulnerability in the page alert function. If a user accesses a crafted URL while logged in to the affected product, an ar…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-50339

Published Dec 26, 2023

Stored cross-site scripting vulnerability exists in the User Management (/admin/users) page of GROWI versions prior to v6.1.11. If this vulnerability is exploited, an arbitrary sc…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-50332

Published Dec 26, 2023

Improper authorization vulnerability exists in the User Management (/admin/users) page of GROWI versions prior to v6.0.6. If this vulnerability is exploited, a user may delete or…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-50294

Published Dec 26, 2023

The App Settings (/admin/app) page in GROWI versions prior to v6.0.6 stores sensitive information in cleartext form. As a result, the Secret access key for external service may be…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-50175

Published Dec 26, 2023

Stored cross-site scripting vulnerability exists in the App Settings (/admin/app) page, the Markdown Settings (/admin/markdown) page, and the Customize (/admin/customize) page of…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-49807

Published Dec 26, 2023

Stored cross-site scripting vulnerability when processing the MathJax exists in GROWI versions prior to v6.0.0. If this vulnerability is exploited, an arbitrary script may be exec…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-49779

Published Dec 26, 2023

Stored cross-site scripting vulnerability exists in the anchor tag of GROWI versions prior to v6.0.0. If this vulnerability is exploited, an arbitrary script may be executed on th…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-49598

Published Dec 26, 2023

Stored cross-site scripting vulnerability exists in the event handlers of the pre tags in GROWI versions prior to v6.0.0. If this vulnerability is exploited, an arbitrary script m…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-49119

Published Dec 26, 2023

Stored cross-site scripting vulnerability via the img tags exists in GROWI versions prior to v6.0.0. If this vulnerability is exploited, an arbitrary script may be executed on the…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-47215

Published Dec 26, 2023

Stored cross-site scripting vulnerability which is exploiting a behavior of the XSS Filter exists in GROWI versions prior to v6.0.0. If this vulnerability is exploited, an arbitra…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-46699

Published Dec 26, 2023

Cross-site request forgery (CSRF) vulnerability exists in the User settings (/me) page of GROWI versions prior to v6.0.0. If a user views a malicious page while logging in, settin…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-45740

Published Dec 26, 2023

Stored cross-site scripting vulnerability when processing profile images exists in GROWI versions prior to v4.1.3. If this vulnerability is exploited, an arbitrary script may be e…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-45737

Published Dec 26, 2023

Stored cross-site scripting vulnerability exists in the App Settings (/admin/app) page and the Markdown Settings (/admin/markdown) page of GROWI versions prior to v3.5.0. If this…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-42436

Published Dec 26, 2023

Stored cross-site scripting vulnerability exists in the presentation feature of GROWI versions prior to v3.4.0. If this vulnerability is exploited, an arbitrary script may be exec…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-41799

Published Oct 24, 2022

Improper access control vulnerability in GROWI prior to v5.1.4 (v5 series) and versions prior to v4.5.25 (v4 series) allows a remote authenticated attacker to bypass access restri…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-1236

Published Apr 5, 2022

Weak Password Requirements in GitHub repository weseek/growi prior to v5.0.0.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-3852

Published Jan 12, 2022

growi is vulnerable to Authorization Bypass Through User-Controlled Key

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-20829

Published Sep 21, 2021

Cross-site scripting vulnerability due to the inadequate tag sanitization in GROWI versions v4.2.19 and earlier allows remote attackers to execute an arbitrary script on the web b…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-20737

Published Jun 22, 2021

Improper authentication vulnerability in GROWI versions prior to v4.2.20 allows a remote attacker to view the unauthorized pages without access privileges via unspecified vectors.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-20736

Published Jun 22, 2021

NoSQL injection vulnerability in GROWI versions prior to v4.2.20 allows a remote attacker to obtain and/or alter the information stored in the database via unspecified vectors.

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-20673

Published Mar 10, 2021

Stored cross-site scripting vulnerability in Admin Page of GROWI (v4.2 Series) versions from v4.2.0 to v4.2.7 allows remote authenticated attackers to inject an arbitrary script v…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-20672

Published Mar 10, 2021

Reflected cross-site scripting vulnerability due to insufficient verification of URL query parameters in GROWI (v4.2 Series) versions from v4.2.0 to v4.2.7 allows remote attackers…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-20671

Published Mar 10, 2021

Invalid file validation on the upload feature in GROWI versions v4.2.2 allows a remote attacker with administrative privilege to overwrite the files on the server, which may lead…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2021-20670

Published Mar 10, 2021

Improper access control vulnerability in GROWI versions v4.2.2 and earlier allows a remote unauthenticated attacker to read the user's personal information and/or server's interna…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-20669

Published Mar 10, 2021

Path traversal vulnerability in GROWI versions v4.2.2 and earlier allows an attacker with administrator rights to read and/or delete an arbitrary path via a specially crafted URL.

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 43 CVEsPage 1 of 2