Products: 1
    Vulnerabilities: 12
    Known Exploited: 0
    0
    Critical Level Threats
    4
    High Level Threats
    8
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-84205

    GROWI through 8.0.2 Authorization Bypass Through User-Controlled Key on apiv3 Revision Retrieval

    Last Modified: Sep 02, 2026
    Published: Sep 01, 2026

    CVE-2026-84204

    GROWI through 8.0.2 Missing Authorization on apiv3 Attachment Retrieval

    Last Modified: Sep 02, 2026
    Published: Sep 01, 2026

    CVE-2026-53620

    GROWI contains a vulnerability with an authorization bypass through user-controlled key in the bookmark folder APIs. If this vulnerability is exploited, an authenticated attacker could retrieve, tamper with, and/or delete the other user's bookmark data.

    Last Modified: Aug 31, 2026
    Published: Aug 31, 2026

    CVE-2026-68951

    Authorization Bypass Exposes Unauthenticated Bookmark Data

    Last Modified: Aug 31, 2026
    Published: Aug 31, 2026

    CVE-2026-80191

    GROWI before 8.0.2 Missing Authorization on Attachment Retrieval for Unauthenticated Requests

    Last Modified: Aug 26, 2026
    Published: Aug 25, 2026
    Items Per Page
    Growi Vulnerabilities & Security CVEs | CVE-DB