Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Grocy

First CVE: Oct 14, 2020Active for: 6 yearsTotal CVEs: 12

Grocy is a self-hosted personal grocery and household management application with a narrow, focused vulnerability footprint concentrated in a single product. The observed weakness class centers on cross-site scripting in web-page generation, a characteristic input-handling gap in web applications. Current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
12
Total CVEs
Bottom 1%
3.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
6.3
Avg CVSS Score
Higher Avg CVSS Score than 8% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Grocy over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 14, 2020
5 years ago
Most Recent CVE
Jan 6, 2025
564 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (12 CVEs).

12 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-55074CRITICAL
The edit profile function of Grocy through 4.3.0 allows stored XSS and resultant privilege escalation by uploading a crafted HTML or SVG file, a different issue than CVE-2024-8370.
Jan 6, 20259.024NONO
CVE-2023-42270HIGH
Grocy <= 4.0.2 is vulnerable to Cross Site Request Forgery (CSRF).
Sep 15, 20238.824NONO
CVE-2023-48199HIGH
HTML Injection vulnerability in the 'manageApiKeys' component in Grocy <= 4.0.3 allows attackers to inject arbitrary HTML content without script execution. This occurs when user-su
Nov 15, 20237.823NONO
CVE-2024-55076HIGH
Grocy through 4.3.0 has no CSRF protection, as demonstrated by changing the Administrator's password.
Jan 6, 20258.122NONO
CVE-2024-8370MEDIUM
A vulnerability classified as problematic was found in Grocy up to 4.2.0. This vulnerability affects unknown code of the file /api/files/recipepictures/ of the component SVG File U
Sep 1, 20245.419NONO
CVE-2023-48198MEDIUM
A Cross-Site Scripting (XSS) vulnerability in the 'product description' component within '/api/stock/products' of Grocy version <= 4.0.3 allows attackers to obtain a victim's cooki
Nov 15, 20235.419NONO
CVE-2023-48197MEDIUM
Cross-Site Scripting (XSS) vulnerability in the ‘manageApiKeys’ component of Grocy 4.0.3 and earlier allows attackers to obtain victim's cookies when the victim clicks on the "see
Nov 15, 20235.419NONO
CVE-2020-25454MEDIUM
Cross-site Scripting (XSS) vulnerability in grocy 2.7.1 via the add recipe module, which gets executed when deleting the recipe.
Nov 18, 20205.418NONO
CVE-2024-55075MEDIUM
Grocy through 4.3.0 allows remote attackers to obtain sensitive information via direct requests to pages that are not shown in the UI, such as calendar and recipes.
Jan 6, 20255.317NONO
CVE-2023-48866MEDIUM
A Cross-Site Scripting (XSS) vulnerability in the recipe preparation component within /api/objects/recipes and note component within /api/objects/shopping_lists/ of Grocy <= 4.0.3
Dec 4, 20235.417NONO
View all 12 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products12 CVEs
67%
25%
8%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (8.3%)
Network11 (91.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (91.7%)
High1 (8.3%)
Unknown0 (0.0%)
User Interaction
None3 (25.0%)
Unknown0 (0.0%)
Required9 (75.0%)
Privileges Required
Low8 (66.7%)
High1 (8.3%)
None3 (25.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (12 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Grocy.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Grocy — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Grocy's Products

View all 3 CNAs →

Top CWEs