Show filters
42 Total Results
Displaying 11-20 of 42
Sort by:
Attacker Value
Unknown
CVE-2023-45740
Disclosure Date: December 26, 2023 (last updated January 05, 2024)
Stored cross-site scripting vulnerability when processing profile images exists in GROWI versions prior to v4.1.3. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the site using the product.
0
Attacker Value
Unknown
CVE-2023-45737
Disclosure Date: December 26, 2023 (last updated January 05, 2024)
Stored cross-site scripting vulnerability exists in the App Settings (/admin/app) page and the Markdown Settings (/admin/markdown) page of GROWI versions prior to v3.5.0. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the site using the product.
0
Attacker Value
Unknown
CVE-2023-42436
Disclosure Date: December 26, 2023 (last updated January 05, 2024)
Stored cross-site scripting vulnerability exists in the presentation feature of GROWI versions prior to v3.4.0. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the site using the product.
0
Attacker Value
Unknown
CVE-2022-41799
Disclosure Date: October 24, 2022 (last updated October 08, 2023)
Improper access control vulnerability in GROWI prior to v5.1.4 (v5 series) and versions prior to v4.5.25 (v4 series) allows a remote authenticated attacker to bypass access restriction and download the markdown data from the pages set to private by the other users.
0
Attacker Value
Unknown
CVE-2022-1236
Disclosure Date: April 05, 2022 (last updated February 23, 2025)
Weak Password Requirements in GitHub repository weseek/growi prior to v5.0.0.
0
Attacker Value
Unknown
CVE-2021-3852
Disclosure Date: January 12, 2022 (last updated February 23, 2025)
growi is vulnerable to Authorization Bypass Through User-Controlled Key
0
Attacker Value
Unknown
CVE-2021-20829
Disclosure Date: September 21, 2021 (last updated February 23, 2025)
Cross-site scripting vulnerability due to the inadequate tag sanitization in GROWI versions v4.2.19 and earlier allows remote attackers to execute an arbitrary script on the web browser of the user who accesses a specially crafted page.
0
Attacker Value
Unknown
CVE-2021-20737
Disclosure Date: June 22, 2021 (last updated February 22, 2025)
Improper authentication vulnerability in GROWI versions prior to v4.2.20 allows a remote attacker to view the unauthorized pages without access privileges via unspecified vectors.
0
Attacker Value
Unknown
CVE-2021-20736
Disclosure Date: June 22, 2021 (last updated February 22, 2025)
NoSQL injection vulnerability in GROWI versions prior to v4.2.20 allows a remote attacker to obtain and/or alter the information stored in the database via unspecified vectors.
0
Attacker Value
Unknown
CVE-2021-20673
Disclosure Date: March 10, 2021 (last updated February 22, 2025)
Stored cross-site scripting vulnerability in Admin Page of GROWI (v4.2 Series) versions from v4.2.0 to v4.2.7 allows remote authenticated attackers to inject an arbitrary script via unspecified vectors.
0