Skip to main content

Vendor/product archive

weseek / growi CVEs

Beta · best-effort

43 CVEs tagged to weseek / growi1 Critical, 9 High, 32 Medium, 1 Low, 0 Unrated.

CVE-2021-20668

Published Mar 10, 2021

Path traversal vulnerability in GROWI versions v4.2.2 and earlier allows an attacker with administrator rights to read an arbitrary path via a specially crafted URL.

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-20667

Published Mar 10, 2021

Stored cross-site scripting vulnerability due to inadequate CSP (Content Security Policy) configuration in GROWI versions v4.2.2 and earlier allows remote authenticated attackers…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-20619

Published Jan 19, 2021

Cross-site scripting vulnerability in GROWI (v4.2 Series) versions prior to v4.2.3 allows remote attackers to inject an arbitrary script via unspecified vectors.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-5683

Published Dec 16, 2020

Directory traversal vulnerability in GROWI versions prior to v4.2.3 (v4.2 Series), GROWI versions prior to v4.1.12 (v4.1 Series), and GROWI v3 series and earlier GROWI versions pr…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-5682

Published Dec 16, 2020

Improper input validation in GROWI versions prior to v4.2.3 (v4.2 Series), GROWI versions prior to v4.1.12 (v4.1 Series), and GROWI v3 series and earlier GROWI versions prior to v…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-5678

Published Dec 3, 2020

Stored cross-site scripting vulnerability in GROWI v3.8.1 and earlier allows remote attackers to inject arbitrary script via unspecified vectors.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-5677

Published Dec 3, 2020

Reflected cross-site scripting vulnerability in GROWI v4.0.0 and earlier allows remote attackers to inject arbitrary script via unspecified vectors.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-5676

Published Dec 3, 2020

GROWI v4.1.3 and earlier allow remote attackers to obtain information which is not allowed to access via unspecified vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-13338

Published Jul 9, 2019

In WESEEK GROWI before 3.5.0, a remote attacker can obtain the password hash of the creator of a page by leveraging wiki access to make API calls for page metadata. In other words…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-13337

Published Jul 9, 2019

In WESEEK GROWI before 3.5.0, the site-wide basic authentication can be bypassed by adding a URL parameter access_token (this is the parameter used by the API). No valid token is…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-5969

Published Jul 5, 2019

Open redirect vulnerability in GROWI v3.4.6 and earlier allows remote attackersto redirect users to arbitrary web sites and conduct phishing attacks via the process of login.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-5968

Published Jul 5, 2019

Cross-site request forgery (CSRF) vulnerability in GROWI v3.4.6 and earlier allows remote attackers to hijack the authentication of administrators via updating user's 'Basic Info'.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-16205

Published Jan 9, 2019

Cross-site scripting vulnerability in GROWI v3.2.3 and earlier allows remote attackers to inject arbitrary web script or HTML via New Page modal.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-0698

Published Jan 9, 2019

Cross-site scripting vulnerability in GROWI v3.2.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-0655

Published Sep 7, 2018

Cross-site scripting vulnerability in GROWI v.3.1.11 and earlier allows remote authenticated attackers to inject arbitrary web script or HTML via the app settings section of admin…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-0654

Published Sep 7, 2018

Cross-site scripting vulnerability in GROWI v.3.1.11 and earlier allows remote attackers to inject arbitrary web script or HTML via the modal for creating Wiki page.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-0653

Published Sep 7, 2018

Cross-site scripting vulnerability in GROWI v.3.1.11 and earlier allows remote attackers to inject arbitrary web script or HTML via Wiki page view.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-0652

Published Sep 7, 2018

Cross-site scripting vulnerability in GROWI v.3.1.11 and earlier allows remote authenticated attackers to inject arbitrary web script or HTML via the UserGroup Management section…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 26-43 of 43 CVEsPage 2 of 2