Vulnerability index

Browse CVEs

11 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.1 CVE-2024-55076 Grocy through 4.3.0 has no CSRF protection, as demonstrated by changing the Administrator's password. Grocy after 4.3.0 Fix from $1,9502025-01-06 MEDIUM 5.3 CVE-2024-55075 Grocy through 4.3.0 allows remote attackers to obtain sensitive information via direct requests to pages that are not shown in the UI, such as calend… Grocy after 4.3.0 Fix from $1,6002025-01-06 CRITICAL 9.0 CVE-2024-55074 The edit profile function of Grocy through 4.3.0 allows stored XSS and resultant privilege escalation by uploading a crafted HTML or SVG file, a diff… Grocy after 4.3.0 Fix from $2,3002025-01-06 MEDIUM 5.4 CVE-2024-8370 A vulnerability classified as problematic was found in Grocy up to 4.2.0. This vulnerability affects unknown code of the file /api/files/recipepictur… Grocy after 4.2.0 Fix from $1,6002024-09-01 MEDIUM 5.4 CVE-2023-48866 A Cross-Site Scripting (XSS) vulnerability in the recipe preparation component within /api/objects/recipes and note component within /api/objects/sho… Grocy after 4.0.3 Fix from $1,6002023-12-04 HIGH 7.8 CVE-2023-48199 HTML Injection vulnerability in the 'manageApiKeys' component in Grocy <= 4.0.3 allows attackers to inject arbitrary HTML content without script exec… Grocy No fix yet Fix from $1,9502023-11-15 MEDIUM 5.4 CVE-2023-48200 Cross Site Scripting vulnerability in Grocy v.4.0.3 allows a local attacker to execute arbitrary code and obtain sensitive information via the equipm… Grocy No fix yet Fix from $1,6002023-11-15 MEDIUM 5.4 CVE-2023-48197 Cross-Site Scripting (XSS) vulnerability in the ‘manageApiKeys’ component of Grocy 4.0.3 and earlier allows attackers to obtain victim's cookies when… Grocy No fix yet Fix from $1,6002023-11-15 MEDIUM 5.4 CVE-2023-48198 A Cross-Site Scripting (XSS) vulnerability in the 'product description' component within '/api/stock/products' of Grocy version <= 4.0.3 allows attac… Grocy No fix yet Fix from $1,6002023-11-15 HIGH 8.8 CVE-2023-42270 Grocy <= 4.0.2 is vulnerable to Cross Site Request Forgery (CSRF). Grocy after 4.0.2 Fix from $1,9502023-09-15 MEDIUM 5.4 CVE-2020-25454 Cross-site Scripting (XSS) vulnerability in grocy 2.7.1 via the add recipe module, which gets executed when deleting the recipe. Grocy No fix yet Fix from $1,6002020-11-18