Products: 1
    Vulnerabilities: 44
    Known Exploited: 0
    1
    Critical Level Threats
    10
    High Level Threats
    32
    Medium Level Threats
    1
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-80191

    GROWI before 8.0.2 Missing Authorization on Attachment Retrieval for Unauthenticated Requests

    Last Modified: Aug 26, 2026
    Published: Aug 25, 2026

    CVE-2025-54806

    GROWI v4.2.7 and earlier contains a cross-site scripting vulnerability in the page alert function. If a user accesses a crafted URL while logged in to the affected product, an arbitrary script may be executed on the user's web browser.

    Last Modified: Nov 12, 2025
    Published: Oct 23, 2025

    CVE-2023-42436

    Stored cross-site scripting vulnerability exists in the presentation feature of GROWI versions prior to v3.4.0. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the site using the product.

    Last Modified: Nov 21, 2024
    Published: Dec 26, 2023

    CVE-2023-50332

    Improper authorization vulnerability exists in the User Management (/admin/users) page of GROWI versions prior to v6.0.6. If this vulnerability is exploited, a user may delete or suspend its own account without the user's intention.

    Last Modified: Nov 21, 2024
    Published: Dec 26, 2023

    CVE-2023-50294

    The App Settings (/admin/app) page in GROWI versions prior to v6.0.6 stores sensitive information in cleartext form. As a result, the Secret access key for external service may be obtained by an attacker who can access the App Settings page.

    Last Modified: Nov 21, 2024
    Published: Dec 26, 2023
    Items Per Page