Getgrist is a niche collaborative data platform centered on its Grist Core product, which serves as an open-source alternative to traditional spreadsheet and database tools. Its vulnerability profile reflects the application's web-facing architecture and data-handling role, with recurring weaknesses clustering around cross-site scripting, injection, authorization flaws, and server-side request forgery—attack surface typical of web applications that parse and execute user-supplied content. Vulnerabilities affecting this vendor skew toward serious outcomes, warranting timely review of patches; current severity, exploitation activity, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Getgrist over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-24002CRITICAL Grist is spreadsheet software using Python as its formula language. Grist offers several methods for running those formulas in a sandbox, for cases where the user may be working wi | Jan 22, 2026 | 9.6 | 35 | NO | NO |
CVE-2025-64753MEDIUM grist-core is a spreadsheet hosting server. Prior to version 1.7.7, a user with only partial read access to a document could still access endpoints listing hashes for versions of t | Nov 13, 2025 | 6.5 | 22 | NO | NO |
CVE-2025-64752MEDIUM grist-core is a spreadsheet hosting server. Prior to version 1.7.7, a user with access to any document on a Grist installation can use a feature for fetching from a URL that is exe | Nov 13, 2025 | 6.5 | 22 | NO | NO |
CVE-2024-56359MEDIUM grist-core is a spreadsheet hosting server. A user visiting a malicious document and clicking on a link in a HyperLink cell using a control modifier (meaning for example Ctrl+click | Dec 20, 2024 | 6.1 | 18 | NO | NO |
CVE-2024-56358MEDIUM grist-core is a spreadsheet hosting server. A user visiting a malicious document and previewing an attachment could have their account compromised, because JavaScript in an SVG fil | Dec 20, 2024 | 6.1 | 18 | NO | NO |
CVE-2024-56357MEDIUM grist-core is a spreadsheet hosting server. A user visiting a malicious document or submitting a malicious form could have their account compromised, because it was possible to use | Dec 20, 2024 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Getgrist.
Media articles that mention a CVE ID that affects a product developed by Getgrist — matched by CVE ID, not by vendor name.