Vulnerability index

Browse CVEs

37 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2019-13338 In WESEEK GROWI before 3.5.0, a remote attacker can obtain the password hash of the creator of a page by leveraging wiki access to make API calls for… Growi 3.5.0+ Fix from $1,9502019-07-09 HIGH 8.8 CVE-2019-5968 Cross-site request forgery (CSRF) vulnerability in GROWI v3.4.6 and earlier allows remote attackers to hijack the authentication of administrators vi… Growi after 3.4.6 Fix from $1,9502019-07-05 MEDIUM 6.1 CVE-2019-5969 Open redirect vulnerability in GROWI v3.4.6 and earlier allows remote attackersto redirect users to arbitrary web sites and conduct phishing attacks … Growi after 3.4.6 Fix from $1,6002019-07-05 MEDIUM 5.4 CVE-2018-16205 Cross-site scripting vulnerability in GROWI v3.2.3 and earlier allows remote attackers to inject arbitrary web script or HTML via New Page modal. Growi after 3.2.3 Fix from $1,6002019-01-09 MEDIUM 5.4 CVE-2018-0698 Cross-site scripting vulnerability in GROWI v3.2.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Growi after 3.2.3 Fix from $1,6002019-01-09 MEDIUM 6.1 CVE-2018-0653 Cross-site scripting vulnerability in GROWI v.3.1.11 and earlier allows remote attackers to inject arbitrary web script or HTML via Wiki page view. Growi after 3.1.11 Fix from $1,6002018-09-07 MEDIUM 6.1 CVE-2018-0654 Cross-site scripting vulnerability in GROWI v.3.1.11 and earlier allows remote attackers to inject arbitrary web script or HTML via the modal for cre… Growi after 3.1.11 Fix from $1,6002018-09-07