Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Getgrist

First CVE: Dec 20, 2024Active for: 2 yearsTotal CVEs: 6

Getgrist is a niche collaborative data platform centered on its Grist Core product, which serves as an open-source alternative to traditional spreadsheet and database tools. Its vulnerability profile reflects the application's web-facing architecture and data-handling role, with recurring weaknesses clustering around cross-site scripting, injection, authorization flaws, and server-side request forgery—attack surface typical of web applications that parse and execute user-supplied content. Vulnerabilities affecting this vendor skew toward serious outcomes, warranting timely review of patches; current severity, exploitation activity, and exposure metrics are shown alongside this summary.

FAUCET AI Generated
6
Total CVEs
More Total CVEs than 86% of tracked vendors
2.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
6.8
Avg CVSS Score
Higher Avg CVSS Score than 47% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Getgrist over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 20, 2024
19 months ago
Most Recent CVE
Jan 22, 2026
183 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (6 CVEs).

6 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-24002CRITICAL
Grist is spreadsheet software using Python as its formula language. Grist offers several methods for running those formulas in a sandbox, for cases where the user may be working wi
Jan 22, 20269.635NONO
CVE-2025-64753MEDIUM
grist-core is a spreadsheet hosting server. Prior to version 1.7.7, a user with only partial read access to a document could still access endpoints listing hashes for versions of t
Nov 13, 20256.522NONO
CVE-2025-64752MEDIUM
grist-core is a spreadsheet hosting server. Prior to version 1.7.7, a user with access to any document on a Grist installation can use a feature for fetching from a URL that is exe
Nov 13, 20256.522NONO
CVE-2024-56359MEDIUM
grist-core is a spreadsheet hosting server. A user visiting a malicious document and clicking on a link in a HyperLink cell using a control modifier (meaning for example Ctrl+click
Dec 20, 20246.118NONO
CVE-2024-56358MEDIUM
grist-core is a spreadsheet hosting server. A user visiting a malicious document and previewing an attachment could have their account compromised, because JavaScript in an SVG fil
Dec 20, 20246.118NONO
CVE-2024-56357MEDIUM
grist-core is a spreadsheet hosting server. A user visiting a malicious document or submitting a malicious form could have their account compromised, because it was possible to use
Dec 20, 20246.118NONO
View all 6 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products6 CVEs
83%
17%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumCritical
Attack Vector
Local0 (0.0%)
Network6 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None2 (33.3%)
Unknown0 (0.0%)
Required4 (66.7%)
Privileges Required
Low2 (33.3%)
High0 (0.0%)
None4 (66.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (6 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Getgrist.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Getgrist — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Getgrist's Products

View all 1 CNAs →

Top CWEs