Products: 5
    Vulnerabilities: 7
    Known Exploited: 0
    2
    Critical Level Threats
    2
    High Level Threats
    3
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2023-46131

    Grails® data binding causes JVM crash and/or DoS

    Last Modified: Nov 21, 2024
    Published: Dec 20, 2023

    CVE-2022-41923

    Grails Spring Security Core plugin vulnerable to privilege escalation

    Last Modified: Apr 23, 2025
    Published: Nov 23, 2022

    CVE-2022-35912

    In grails-databinding in Grails before 3.3.15, 4.x before 4.1.1, 5.x before 5.1.9, and 5.2.x before 5.2.1 (at least when certain Java 8 configurations are used), data binding allows a remote attacker to execute code by gaining access to the class loader.

    Last Modified: Nov 21, 2024
    Published: Jul 19, 2022

    CVE-2019-12728

    Grails before 3.3.10 used cleartext HTTP to resolve the SDKMan notification service. NOTE: users' apps were not resolving dependencies over cleartext HTTP.

    Last Modified: Nov 21, 2024
    Published: Jun 04, 2019

    CVE-2018-1000529

    Grails Fields plugin version 2.2.7 contains a Cross Site Scripting (XSS) vulnerability in Using the display tag that can result in XSS . This vulnerability appears to have been fixed in 2.2.8.

    Last Modified: Nov 21, 2024
    Published: Jun 26, 2018
    Items Per Page