Show filters
42 Total Results
Displaying 11-20 of 42
Sort by:
Attacker Value
Unknown

CVE-2023-45740

Disclosure Date: December 26, 2023 (last updated January 05, 2024)
Stored cross-site scripting vulnerability when processing profile images exists in GROWI versions prior to v4.1.3. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the site using the product.
Attacker Value
Unknown

CVE-2023-45737

Disclosure Date: December 26, 2023 (last updated January 05, 2024)
Stored cross-site scripting vulnerability exists in the App Settings (/admin/app) page and the Markdown Settings (/admin/markdown) page of GROWI versions prior to v3.5.0. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the site using the product.
Attacker Value
Unknown

CVE-2023-42436

Disclosure Date: December 26, 2023 (last updated January 05, 2024)
Stored cross-site scripting vulnerability exists in the presentation feature of GROWI versions prior to v3.4.0. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the site using the product.
Attacker Value
Unknown

CVE-2022-41799

Disclosure Date: October 24, 2022 (last updated October 08, 2023)
Improper access control vulnerability in GROWI prior to v5.1.4 (v5 series) and versions prior to v4.5.25 (v4 series) allows a remote authenticated attacker to bypass access restriction and download the markdown data from the pages set to private by the other users.
Attacker Value
Unknown

CVE-2022-1236

Disclosure Date: April 05, 2022 (last updated February 23, 2025)
Weak Password Requirements in GitHub repository weseek/growi prior to v5.0.0.
Attacker Value
Unknown

CVE-2021-3852

Disclosure Date: January 12, 2022 (last updated February 23, 2025)
growi is vulnerable to Authorization Bypass Through User-Controlled Key
Attacker Value
Unknown

CVE-2021-20829

Disclosure Date: September 21, 2021 (last updated February 23, 2025)
Cross-site scripting vulnerability due to the inadequate tag sanitization in GROWI versions v4.2.19 and earlier allows remote attackers to execute an arbitrary script on the web browser of the user who accesses a specially crafted page.
Attacker Value
Unknown

CVE-2021-20737

Disclosure Date: June 22, 2021 (last updated February 22, 2025)
Improper authentication vulnerability in GROWI versions prior to v4.2.20 allows a remote attacker to view the unauthorized pages without access privileges via unspecified vectors.
Attacker Value
Unknown

CVE-2021-20736

Disclosure Date: June 22, 2021 (last updated February 22, 2025)
NoSQL injection vulnerability in GROWI versions prior to v4.2.20 allows a remote attacker to obtain and/or alter the information stored in the database via unspecified vectors.
Attacker Value
Unknown

CVE-2021-20673

Disclosure Date: March 10, 2021 (last updated February 22, 2025)
Stored cross-site scripting vulnerability in Admin Page of GROWI (v4.2 Series) versions from v4.2.0 to v4.2.7 allows remote authenticated attackers to inject an arbitrary script via unspecified vectors.