Vulnerability index

Browse CVEs

37 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2025-54806 GROWI v4.2.7 and earlier contains a cross-site scripting vulnerability in the page alert function. If a user accesses a crafted URL while logged in … Growi 4.2.8+ Fix from $1,6002025-10-23 MEDIUM 6.5 CVE-2023-50294 The App Settings (/admin/app) page in GROWI versions prior to v6.0.6 stores sensitive information in cleartext form. As a result, the Secret access k… Growi 6.0.6+ Fix from $1,6002023-12-26 MEDIUM 6.5 CVE-2023-50332 Improper authorization vulnerability exists in the User Management (/admin/users) page of GROWI versions prior to v6.0.6. If this vulnerability is ex… Growi 6.0.6+ Fix from $1,6002023-12-26 MEDIUM 5.4 CVE-2023-49779 Stored cross-site scripting vulnerability exists in the anchor tag of GROWI versions prior to v6.0.0. If this vulnerability is exploited, an arbitrar… Growi 6.0.0+ Fix from $1,6002023-12-26 MEDIUM 5.4 CVE-2023-49807 Stored cross-site scripting vulnerability when processing the MathJax exists in GROWI versions prior to v6.0.0. If this vulnerability is exploited, a… Growi 6.0.0+ Fix from $1,6002023-12-26 MEDIUM 5.4 CVE-2023-50175 Stored cross-site scripting vulnerability exists in the App Settings (/admin/app) page, the Markdown Settings (/admin/markdown) page, and the Customi… Growi 6.0.0+ Fix from $1,6002023-12-26 MEDIUM 5.4 CVE-2023-50339 Stored cross-site scripting vulnerability exists in the User Management (/admin/users) page of GROWI versions prior to v6.1.11. If this vulnerability… Growi 6.1.11+ Fix from $1,6002023-12-26 MEDIUM 5.4 CVE-2023-45740 Stored cross-site scripting vulnerability when processing profile images exists in GROWI versions prior to v4.1.3. If this vulnerability is exploited… Growi 4.1.3+ Fix from $1,6002023-12-26 MEDIUM 5.4 CVE-2023-47215 Stored cross-site scripting vulnerability which is exploiting a behavior of the XSS Filter exists in GROWI versions prior to v6.0.0. If this vulnerab… Growi 6.0.0+ Fix from $1,6002023-12-26 MEDIUM 5.4 CVE-2023-49119 Stored cross-site scripting vulnerability via the img tags exists in GROWI versions prior to v6.0.0. If this vulnerability is exploited, an arbitrary… Growi 6.0.0+ Fix from $1,6002023-12-26 MEDIUM 5.4 CVE-2023-49598 Stored cross-site scripting vulnerability exists in the event handlers of the pre tags in GROWI versions prior to v6.0.0. If this vulnerability is ex… Growi 6.0.0+ Fix from $1,6002023-12-26 MEDIUM 5.4 CVE-2023-42436 Stored cross-site scripting vulnerability exists in the presentation feature of GROWI versions prior to v3.4.0. If this vulnerability is exploited, a… Growi 3.4.0+ Fix from $1,6002023-12-26 MEDIUM 5.4 CVE-2023-45737 Stored cross-site scripting vulnerability exists in the App Settings (/admin/app) page and the Markdown Settings (/admin/markdown) page of GROWI vers… Growi 3.5.0+ Fix from $1,6002023-12-26 MEDIUM 6.5 CVE-2022-41799 Improper access control vulnerability in GROWI prior to v5.1.4 (v5 series) and versions prior to v4.5.25 (v4 series) allows a remote authenticated at… Growi 4.5.25 / 5.1.4+ Fix from $1,6002022-10-24 MEDIUM 6.5 CVE-2022-1236 Weak Password Requirements in GitHub repository weseek/growi prior to v5.0.0. Growi 5.0.0+ Fix from $1,6002022-04-05 HIGH 7.5 CVE-2021-3852 growi is vulnerable to Authorization Bypass Through User-Controlled Key Growi after 4.4.7 Fix from $1,9502022-01-12 MEDIUM 6.1 CVE-2021-20829 Cross-site scripting vulnerability due to the inadequate tag sanitization in GROWI versions v4.2.19 and earlier allows remote attackers to execute an… Growi after 4.2.19 Fix from $1,6002021-09-21 CRITICAL 9.1 CVE-2021-20736 NoSQL injection vulnerability in GROWI versions prior to v4.2.20 allows a remote attacker to obtain and/or alter the information stored in the databa… Growi 4.2.20+ Fix from $2,3002021-06-22 MEDIUM 6.5 CVE-2021-20737 Improper authentication vulnerability in GROWI versions prior to v4.2.20 allows a remote attacker to view the unauthorized pages without access privi… Growi 4.2.20+ Fix from $1,6002021-06-22 HIGH 7.5 CVE-2021-20670 Improper access control vulnerability in GROWI versions v4.2.2 and earlier allows a remote unauthenticated attacker to read the user's personal infor… Growi after 4.2.2 Fix from $1,9502021-03-10 HIGH 7.2 CVE-2021-20671 Invalid file validation on the upload feature in GROWI versions v4.2.2 allows a remote attacker with administrative privilege to overwrite the files … Growi Mitigation only Fix from $1,9502021-03-10 MEDIUM 6.1 CVE-2021-20672 Reflected cross-site scripting vulnerability due to insufficient verification of URL query parameters in GROWI (v4.2 Series) versions from v4.2.0 to … Growi after 4.2.7 Fix from $1,6002021-03-10 MEDIUM 5.4 CVE-2021-20667 Stored cross-site scripting vulnerability due to inadequate CSP (Content Security Policy) configuration in GROWI versions v4.2.2 and earlier allows r… Growi after 4.2.2 Fix from $1,6002021-03-10 MEDIUM 6.1 CVE-2021-20619 Cross-site scripting vulnerability in GROWI (v4.2 Series) versions prior to v4.2.3 allows remote attackers to inject an arbitrary script via unspecif… Growi 4.2.3+ Fix from $1,6002021-01-19 HIGH 7.5 CVE-2020-5683 Directory traversal vulnerability in GROWI versions prior to v4.2.3 (v4.2 Series), GROWI versions prior to v4.1.12 (v4.1 Series), and GROWI v3 series… Growi 4.1.12 / 4.2.3+ Fix from $1,9502020-12-16 HIGH 7.5 CVE-2020-5682 Improper input validation in GROWI versions prior to v4.2.3 (v4.2 Series), GROWI versions prior to v4.1.12 (v4.1 Series), and GROWI v3 series and ear… Growi 4.1.12 / 4.2.3+ Fix from $1,9502020-12-16 HIGH 7.5 CVE-2020-5676 GROWI v4.1.3 and earlier allow remote attackers to obtain information which is not allowed to access via unspecified vectors. Growi after 4.1.3 Fix from $1,9502020-12-03 MEDIUM 6.1 CVE-2020-5677 Reflected cross-site scripting vulnerability in GROWI v4.0.0 and earlier allows remote attackers to inject arbitrary script via unspecified vectors. Growi after 4.0.0 Fix from $1,6002020-12-03 MEDIUM 6.1 CVE-2020-5678 Stored cross-site scripting vulnerability in GROWI v3.8.1 and earlier allows remote attackers to inject arbitrary script via unspecified vectors. Growi after 3.8.1 Fix from $1,6002020-12-03 HIGH 7.5 CVE-2019-13337 In WESEEK GROWI before 3.5.0, the site-wide basic authentication can be bypassed by adding a URL parameter access_token (this is the parameter used b… Growi 3.5.0+ Fix from $1,9502019-07-09