Weseek develops Growi, a modestly represented wiki and knowledge-management platform that has accumulated a meaningful vulnerability footprint despite narrow product scope. The platform's exposure recurs through application-layer weakness classes including cross-site scripting, path traversal, authorization bypass, and cross-site request forgery, reflecting the input-handling and access-control demands of web-based collaborative software. A moderate share of the vendor's disclosures reach serious severity, consistent with the authentication and data-integrity risks inherent to knowledge repositories. Defenders deploying Growi should prioritize input validation and access-control hardening, particularly for user-generated content and administrative functions; live severity and exploitation details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Weseek over time
Signals from CVEs in this vendor scope (43 CVEs).
43 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-20736CRITICAL NoSQL injection vulnerability in GROWI versions prior to v4.2.20 allows a remote attacker to obtain and/or alter the information stored in the database via unspecified vectors. | Jun 22, 2021 | 9.1 | 27 | NO | NO |
CVE-2019-5968HIGH Cross-site request forgery (CSRF) vulnerability in GROWI v3.4.6 and earlier allows remote attackers to hijack the authentication of administrators via updating user's 'Basic Info'. | Jul 5, 2019 | 8.8 | 27 | NO | NO |
CVE-2021-3852HIGH growi is vulnerable to Authorization Bypass Through User-Controlled Key | Jan 12, 2022 | 7.5 | 25 | NO | NO |
CVE-2021-20671HIGH Invalid file validation on the upload feature in GROWI versions v4.2.2 allows a remote attacker with administrative privilege to overwrite the files on the server, which may lead t | Mar 10, 2021 | 7.2 | 24 | NO | NO |
CVE-2021-20670HIGH Improper access control vulnerability in GROWI versions v4.2.2 and earlier allows a remote unauthenticated attacker to read the user's personal information and/or server's internal | Mar 10, 2021 | 7.5 | 24 | NO | NO |
CVE-2022-41799MEDIUM Improper access control vulnerability in GROWI prior to v5.1.4 (v5 series) and versions prior to v4.5.25 (v4 series) allows a remote authenticated attacker to bypass access restric | Oct 24, 2022 | 6.5 | 23 | NO | NO |
CVE-2019-13338HIGH In WESEEK GROWI before 3.5.0, a remote attacker can obtain the password hash of the creator of a page by leveraging wiki access to make API calls for page metadata. In other words, | Jul 9, 2019 | 7.5 | 23 | NO | NO |
CVE-2019-13337HIGH In WESEEK GROWI before 3.5.0, the site-wide basic authentication can be bypassed by adding a URL parameter access_token (this is the parameter used by the API). No valid token is r | Jul 9, 2019 | 7.5 | 23 | NO | NO |
CVE-2022-1236MEDIUM Weak Password Requirements in GitHub repository weseek/growi prior to v5.0.0. | Apr 5, 2022 | 6.5 | 22 | NO | NO |
CVE-2021-20737MEDIUM Improper authentication vulnerability in GROWI versions prior to v4.2.20 allows a remote attacker to view the unauthorized pages without access privileges via unspecified vectors. | Jun 22, 2021 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (43 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Weseek.
Media articles that mention a CVE ID that affects a product developed by Weseek — matched by CVE ID, not by vendor name.