Gridea is a static site generator and blogging platform with a narrow vulnerability footprint centered on its single product, where the observed exposure reflects web-application input-handling risks including code injection and cross-site scripting. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gridea over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-40274HIGH Gridea version 0.9.3 allows an external attacker to execute arbitrary code remotely on any client attempting to view a malicious markdown file through Gridea. This is possible beca | Sep 30, 2022 | 7.8 | 25 | NO | NO |
CVE-2019-12047MEDIUM Gridea v0.8.0 has an XSS vulnerability through which the Nodejs module can be called to achieve arbitrary code execution, as demonstrated by child_process.exec and the "<img src=# | May 13, 2019 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gridea.
Media articles that mention a CVE ID that affects a product developed by Gridea — matched by CVE ID, not by vendor name.