Growi
Vendor:
First CVE: Sep 7, 2018 · Active for 7 years
43
Total CVEs
More Total CVEs than 98% of tracked products
6.1
Avg CVEs / Year
Higher CVE frequency than 93% of tracked products
6.1
Avg CVSS
Higher Avg CVSS than 25% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Growi over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 7, 2018
7 years ago
Most Recent CVE
Oct 23, 2025
278 days ago
CVE Severity & Scoring
Growi43 CVEs
74%
21%
All CVEs353,240 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network43 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low43 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None15 (34.9%)
Unknown0 (0.0%)
Required28 (65.1%)
Privileges Required
Low16 (37.2%)
High6 (14.0%)
None21 (48.8%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (43 CVEs).
43 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-20736CRITICAL NoSQL injection vulnerability in GROWI versions prior to v4.2.20 allows a remote attacker to obtain and/or alter the information stored in the database via unspecified vectors. | Jun 22, 2021 | 9.1 | 27 | NO | NO |
CVE-2019-5968HIGH Cross-site request forgery (CSRF) vulnerability in GROWI v3.4.6 and earlier allows remote attackers to hijack the authentication of administrators via updating user's 'Basic Info'. | Jul 5, 2019 | 8.8 | 27 | NO | NO |
CVE-2021-3852HIGH growi is vulnerable to Authorization Bypass Through User-Controlled Key | Jan 12, 2022 | 7.5 | 25 | NO | NO |
CVE-2021-20671HIGH Invalid file validation on the upload feature in GROWI versions v4.2.2 allows a remote attacker with administrative privilege to overwrite the files on the server, which may lead t | Mar 10, 2021 | 7.2 | 24 | NO | NO |
CVE-2021-20670HIGH Improper access control vulnerability in GROWI versions v4.2.2 and earlier allows a remote unauthenticated attacker to read the user's personal information and/or server's internal | Mar 10, 2021 | 7.5 | 24 | NO | NO |
CVE-2022-41799MEDIUM Improper access control vulnerability in GROWI prior to v5.1.4 (v5 series) and versions prior to v4.5.25 (v4 series) allows a remote authenticated attacker to bypass access restric | Oct 24, 2022 | 6.5 | 23 | NO | NO |
CVE-2019-13338HIGH In WESEEK GROWI before 3.5.0, a remote attacker can obtain the password hash of the creator of a page by leveraging wiki access to make API calls for page metadata. In other words, | Jul 9, 2019 | 7.5 | 23 | NO | NO |
CVE-2019-13337HIGH In WESEEK GROWI before 3.5.0, the site-wide basic authentication can be bypassed by adding a URL parameter access_token (this is the parameter used by the API). No valid token is r | Jul 9, 2019 | 7.5 | 23 | NO | NO |
CVE-2022-1236MEDIUM Weak Password Requirements in GitHub repository weseek/growi prior to v5.0.0. | Apr 5, 2022 | 6.5 | 22 | NO | NO |
CVE-2021-20737MEDIUM Improper authentication vulnerability in GROWI versions prior to v4.2.20 allows a remote attacker to view the unauthorized pages without access privileges via unspecified vectors. | Jun 22, 2021 | 6.5 | 22 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (43 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (43 CVEs).
Media Mentions
Signals from CVEs in this product scope (43 CVEs).
Top CNAs Publishing CVEs For Growi
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 4.2.2 | 1 | 7.2 | 1.8% | 0 | 0 |