Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
weseek growi vulnerabilities and exploits
(subscribe to this query)
5
CVSSv2
CVE-2021-20670
Improper access control vulnerability in GROWI versions v4.2.2 and previous versions allows a remote unauthenticated malicious user to read the user's personal information and/or server's internal information via unspecified vectors.
Weseek Growi
4.3
CVSSv2
CVE-2021-20672
Reflected cross-site scripting vulnerability due to insufficient verification of URL query parameters in GROWI (v4.2 Series) versions from v4.2.0 to v4.2.7 allows remote malicious users to inject an arbitrary script via unspecified vectors.
Weseek Growi
3.5
CVSSv2
CVE-2021-20673
Stored cross-site scripting vulnerability in Admin Page of GROWI (v4.2 Series) versions from v4.2.0 to v4.2.7 allows remote authenticated malicious users to inject an arbitrary script via unspecified vectors.
Weseek Growi
3.5
CVSSv2
CVE-2018-0652
Cross-site scripting vulnerability in GROWI v.3.1.11 and previous versions allows remote authenticated malicious users to inject arbitrary web script or HTML via the UserGroup Management section of admin page.
Weseek Growi
4.3
CVSSv2
CVE-2018-0653
Cross-site scripting vulnerability in GROWI v.3.1.11 and previous versions allows remote malicious users to inject arbitrary web script or HTML via Wiki page view.
Weseek Growi
4.3
CVSSv2
CVE-2018-0654
Cross-site scripting vulnerability in GROWI v.3.1.11 and previous versions allows remote malicious users to inject arbitrary web script or HTML via the modal for creating Wiki page.
Weseek Growi
3.5
CVSSv2
CVE-2018-0655
Cross-site scripting vulnerability in GROWI v.3.1.11 and previous versions allows remote authenticated malicious users to inject arbitrary web script or HTML via the app settings section of admin page.
Weseek Growi
NA
CVE-2022-41799
Improper access control vulnerability in GROWI prior to v5.1.4 (v5 series) and versions prior to v4.5.25 (v4 series) allows a remote authenticated malicious user to bypass access restriction and download the markdown data from the pages set to private by the other users.
Weseek Growi
6.8
CVSSv2
CVE-2019-5968
Cross-site request forgery (CSRF) vulnerability in GROWI v3.4.6 and previous versions allows remote malicious users to hijack the authentication of administrators via updating user's 'Basic Info'.
Weseek Growi
5.8
CVSSv2
CVE-2019-5969
Open redirect vulnerability in GROWI v3.4.6 and previous versions allows remote attackersto redirect users to arbitrary web sites and conduct phishing attacks via the process of login.
Weseek Growi
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-32886
insecure direct object reference
CVE-2024-34342
file inclusion
CVE-2024-34562
CVE-2024-34347
CVE-2024-26026
CVE-2024-4647
unprivileged
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
NEXT »