Vulnerability index

Browse CVEs

11 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Grocy HIGH 8.1
CVE-2024-55076

Grocy through 4.3.0 has no CSRF protection, as demonstrated by changing the Administrator's password.

Fix: after 4.3.0
Fix from $1,950 2025-01-06
Grocy MEDIUM 5.3
CVE-2024-55075

Grocy through 4.3.0 allows remote attackers to obtain sensitive information via direct requests to pages that are not shown in the UI, such as calend…

Fix: after 4.3.0
Fix from $1,600 2025-01-06
Grocy CRITICAL 9.0
CVE-2024-55074

The edit profile function of Grocy through 4.3.0 allows stored XSS and resultant privilege escalation by uploading a crafted HTML or SVG file, a diff…

Fix: after 4.3.0
Fix from $2,300 2025-01-06
Grocy MEDIUM 5.4
CVE-2024-8370

A vulnerability classified as problematic was found in Grocy up to 4.2.0. This vulnerability affects unknown code of the file /api/files/recipepictur…

Fix: after 4.2.0
Fix from $1,600 2024-09-01
Grocy MEDIUM 5.4
CVE-2023-48866

A Cross-Site Scripting (XSS) vulnerability in the recipe preparation component within /api/objects/recipes and note component within /api/objects/sho…

Fix: after 4.0.3
Fix from $1,600 2023-12-04
Grocy HIGH 7.8
CVE-2023-48199

HTML Injection vulnerability in the 'manageApiKeys' component in Grocy <= 4.0.3 allows attackers to inject arbitrary HTML content without script exec…

No fix yet
Fix from $1,950 2023-11-15
Grocy MEDIUM 5.4
CVE-2023-48200

Cross Site Scripting vulnerability in Grocy v.4.0.3 allows a local attacker to execute arbitrary code and obtain sensitive information via the equipm…

No fix yet
Fix from $1,600 2023-11-15
Grocy MEDIUM 5.4
CVE-2023-48197

Cross-Site Scripting (XSS) vulnerability in the ‘manageApiKeys’ component of Grocy 4.0.3 and earlier allows attackers to obtain victim's cookies when…

No fix yet
Fix from $1,600 2023-11-15
Grocy MEDIUM 5.4
CVE-2023-48198

A Cross-Site Scripting (XSS) vulnerability in the 'product description' component within '/api/stock/products' of Grocy version <= 4.0.3 allows attac…

No fix yet
Fix from $1,600 2023-11-15
Grocy HIGH 8.8
CVE-2023-42270

Grocy <= 4.0.2 is vulnerable to Cross Site Request Forgery (CSRF).

Fix: after 4.0.2
Fix from $1,950 2023-09-15
Grocy MEDIUM 5.4
CVE-2020-25454

Cross-site Scripting (XSS) vulnerability in grocy 2.7.1 via the add recipe module, which gets executed when deleting the recipe.

No fix yet
Fix from $1,600 2020-11-18