weseek CVE 脆弱性と CVE 一覧(43)

製品(CPE): — CVE 件数: 43

weseek 脆弱性概要

weseek 関連製品全体の CVE とセキュリティ脆弱性情報を集約し、CVSS、EPSS、公開日、脆弱性情報データを掲載しています。

一般的な弱点パターンには パス処理の欠陥、vendor risk csrf、vendor risk input validation, and vendor risk open redirect があり、vendor surface production workloads and vendor surface software deployment の利用場面で vendor impact session compromise、ファイル上書き, and vendor impact unexpected behavior などのリスクが生じる可能性があります。

掲載データは公開脆弱性情報とセキュリティ公告に基づき、過去の暴露面と修補優先度の評価に利用できます。

脆弱性分布の推移(直近24か月)

表示中 120 / 43 CVE 件数
«« 先頭 « 前へ 1 / 3 次へ »
CVE 概要 ソース CVSS 最大値 EPSS(%) 公開 更新
CVE-2025-54806 GROWI v4.2.7 and earlier contains a cross-site scripting vulnerability in the page alert function. If a user accesses a crafted URL while logged in to the affected product, an arbitrary script may be executed on the user's web browser. [email protected] 5.1 0.16% 2025-10-23 2026-06-17
CVE-2023-50339 Stored cross-site scripting vulnerability exists in the User Management (/admin/users) page of GROWI versions prior to v6.1.11. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the site using the product. [email protected] 5.4 0.30% 2023-12-26 2026-06-17
CVE-2023-50332 Improper authorization vulnerability exists in the User Management (/admin/users) page of GROWI versions prior to v6.0.6. If this vulnerability is exploited, a user may delete or suspend its own account without the user's intention. [email protected] 6.5 0.45% 2023-12-26 2026-06-17
CVE-2023-50294 The App Settings (/admin/app) page in GROWI versions prior to v6.0.6 stores sensitive information in cleartext form. As a result, the Secret access key for external service may be obtained by an attacker who can access the App Settings page. [email protected] 6.5 0.32% 2023-12-26 2026-06-17
CVE-2023-50175 Stored cross-site scripting vulnerability exists in the App Settings (/admin/app) page, the Markdown Settings (/admin/markdown) page, and the Customize (/admin/customize) page of GROWI versions prior to v6.0.0. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the site using the product. [email protected] 5.4 0.30% 2023-12-26 2026-06-17
CVE-2023-49807 Stored cross-site scripting vulnerability when processing the MathJax exists in GROWI versions prior to v6.0.0. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the site using the product. [email protected] 5.4 0.30% 2023-12-26 2026-06-17
CVE-2023-49779 Stored cross-site scripting vulnerability exists in the anchor tag of GROWI versions prior to v6.0.0. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the site using the product. [email protected] 5.4 0.34% 2023-12-26 2026-06-17
CVE-2023-49598 Stored cross-site scripting vulnerability exists in the event handlers of the pre tags in GROWI versions prior to v6.0.0. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the site using the product. [email protected] 5.4 0.30% 2023-12-26 2026-06-17
CVE-2023-49119 Stored cross-site scripting vulnerability via the img tags exists in GROWI versions prior to v6.0.0. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the site using the product. [email protected] 5.4 0.36% 2023-12-26 2026-06-17
CVE-2023-47215 Stored cross-site scripting vulnerability which is exploiting a behavior of the XSS Filter exists in GROWI versions prior to v6.0.0. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the site using the product. [email protected] 5.4 0.34% 2023-12-26 2026-06-17
CVE-2023-46699 Cross-site request forgery (CSRF) vulnerability exists in the User settings (/me) page of GROWI versions prior to v6.0.0. If a user views a malicious page while logging in, settings may be changed without the user's intention. [email protected] 4.3 0.15% 2023-12-26 2026-06-17
CVE-2023-45740 Stored cross-site scripting vulnerability when processing profile images exists in GROWI versions prior to v4.1.3. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the site using the product. [email protected] 5.4 0.30% 2023-12-26 2026-06-17
CVE-2023-45737 Stored cross-site scripting vulnerability exists in the App Settings (/admin/app) page and the Markdown Settings (/admin/markdown) page of GROWI versions prior to v3.5.0. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the site using the product. [email protected] 5.4 0.30% 2023-12-26 2026-06-17
CVE-2023-42436 Stored cross-site scripting vulnerability exists in the presentation feature of GROWI versions prior to v3.4.0. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the site using the product. [email protected] 5.4 0.30% 2023-12-26 2026-06-17
CVE-2022-41799 Improper access control vulnerability in GROWI prior to v5.1.4 (v5 series) and versions prior to v4.5.25 (v4 series) allows a remote authenticated attacker to bypass access restriction and download the markdown data from the pages set to private by the other users. [email protected] 6.5 0.78% 2022-10-24 2026-06-17
CVE-2022-1236 Weak Password Requirements in GitHub repository weseek/growi prior to v5.0.0. [email protected] 6.5 0.52% 2022-04-05 2026-06-17
CVE-2021-3852 growi is vulnerable to Authorization Bypass Through User-Controlled Key [email protected] 7.5 0.81% 2022-01-12 2026-06-17
CVE-2021-20829 Cross-site scripting vulnerability due to the inadequate tag sanitization in GROWI versions v4.2.19 and earlier allows remote attackers to execute an arbitrary script on the web browser of the user who accesses a specially crafted page. [email protected] 6.1 0.73% 2021-09-21 2026-06-16
CVE-2021-20737 Improper authentication vulnerability in GROWI versions prior to v4.2.20 allows a remote attacker to view the unauthorized pages without access privileges via unspecified vectors. [email protected] 6.5 1.05% 2021-06-21 2026-06-16
CVE-2021-20736 NoSQL injection vulnerability in GROWI versions prior to v4.2.20 allows a remote attacker to obtain and/or alter the information stored in the database via unspecified vectors. [email protected] 9.1 1.31% 2021-06-21 2026-06-16
«« 先頭 « 前へ 1 / 3 次へ »
cvelogic Threat Intelligence