Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
growi vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2023-45737
Stored cross-site scripting vulnerability exists in the App Settings (/admin/app) page and the Markdown Settings (/admin/markdown) page of GROWI versions prior to v3.5.0. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who ac...
Weseek Growi
NA
CVE-2023-45740
Stored cross-site scripting vulnerability when processing profile images exists in GROWI versions prior to v4.1.3. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the site using the product.
Weseek Growi
445
VMScore
CVE-2021-3852
growi is vulnerable to Authorization Bypass Through User-Controlled Key
Weseek Growi
312
VMScore
CVE-2018-0652
Cross-site scripting vulnerability in GROWI v.3.1.11 and previous versions allows remote authenticated malicious users to inject arbitrary web script or HTML via the UserGroup Management section of admin page.
Weseek Growi
312
VMScore
CVE-2018-0698
Cross-site scripting vulnerability in GROWI v3.2.3 and previous versions allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Weseek Growi
383
VMScore
CVE-2018-0653
Cross-site scripting vulnerability in GROWI v.3.1.11 and previous versions allows remote malicious users to inject arbitrary web script or HTML via Wiki page view.
Weseek Growi
312
VMScore
CVE-2018-0655
Cross-site scripting vulnerability in GROWI v.3.1.11 and previous versions allows remote authenticated malicious users to inject arbitrary web script or HTML via the app settings section of admin page.
Weseek Growi
570
VMScore
CVE-2022-1236
Weak Password Requirements in GitHub repository weseek/growi prior to v5.0.0.
Weseek Growi
312
VMScore
CVE-2021-20667
Stored cross-site scripting vulnerability due to inadequate CSP (Content Security Policy) configuration in GROWI versions v4.2.2 and previous versions allows remote authenticated malicious users to inject an arbitrary script via a specially crafted content.
Weseek Growi
356
VMScore
CVE-2021-20668
Path traversal vulnerability in GROWI versions v4.2.2 and previous versions allows an attacker with administrator rights to read an arbitrary path via a specially crafted URL.
Weseek Growi
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-30924
CVE-2024-3400
overflow
CVE-2024-23528
CVE-2024-21338
CVE-2024-3818
CVE-2024-23535
NULL pointer dereference
elevation of privilege
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
NEXT »