Vulnerability index

Browse CVEs

37 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Growi HIGH 7.5
CVE-2019-13338

In WESEEK GROWI before 3.5.0, a remote attacker can obtain the password hash of the creator of a page by leveraging wiki access to make API calls for…

Fix: 3.5.0+
Fix from $1,950 2019-07-09
Growi HIGH 8.8
CVE-2019-5968

Cross-site request forgery (CSRF) vulnerability in GROWI v3.4.6 and earlier allows remote attackers to hijack the authentication of administrators vi…

Fix: after 3.4.6
Fix from $1,950 2019-07-05
Growi MEDIUM 6.1
CVE-2019-5969

Open redirect vulnerability in GROWI v3.4.6 and earlier allows remote attackersto redirect users to arbitrary web sites and conduct phishing attacks …

Fix: after 3.4.6
Fix from $1,600 2019-07-05
Growi MEDIUM 5.4
CVE-2018-16205

Cross-site scripting vulnerability in GROWI v3.2.3 and earlier allows remote attackers to inject arbitrary web script or HTML via New Page modal.

Fix: after 3.2.3
Fix from $1,600 2019-01-09
Growi MEDIUM 5.4
CVE-2018-0698

Cross-site scripting vulnerability in GROWI v3.2.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Fix: after 3.2.3
Fix from $1,600 2019-01-09
Growi MEDIUM 6.1
CVE-2018-0653

Cross-site scripting vulnerability in GROWI v.3.1.11 and earlier allows remote attackers to inject arbitrary web script or HTML via Wiki page view.

Fix: after 3.1.11
Fix from $1,600 2018-09-07
Growi MEDIUM 6.1
CVE-2018-0654

Cross-site scripting vulnerability in GROWI v.3.1.11 and earlier allows remote attackers to inject arbitrary web script or HTML via the modal for cre…

Fix: after 3.1.11
Fix from $1,600 2018-09-07