Growi

Vendor:

First CVE: Sep 7, 2018 · Active for 7 years

43
Total CVEs
More Total CVEs than 98% of tracked products
6.1
Avg CVEs / Year
Higher CVE frequency than 93% of tracked products
6.1
Avg CVSS
Higher Avg CVSS than 25% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Growi over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 7, 2018
7 years ago
Most Recent CVE
Oct 23, 2025
278 days ago

CVE Severity & Scoring

Growi43 CVEs
All CVEs353,240 CVEs
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network43 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low43 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None15 (34.9%)
Unknown0 (0.0%)
Required28 (65.1%)
Privileges Required
Low16 (37.2%)
High6 (14.0%)
None21 (48.8%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (43 CVEs).

43 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
NoSQL injection vulnerability in GROWI versions prior to v4.2.20 allows a remote attacker to obtain and/or alter the information stored in the database via unspecified vectors.
Jun 22, 20219.127NONO
Cross-site request forgery (CSRF) vulnerability in GROWI v3.4.6 and earlier allows remote attackers to hijack the authentication of administrators via updating user's 'Basic Info'.
Jul 5, 20198.827NONO
growi is vulnerable to Authorization Bypass Through User-Controlled Key
Jan 12, 20227.525NONO
Invalid file validation on the upload feature in GROWI versions v4.2.2 allows a remote attacker with administrative privilege to overwrite the files on the server, which may lead t
Mar 10, 20217.224NONO
Improper access control vulnerability in GROWI versions v4.2.2 and earlier allows a remote unauthenticated attacker to read the user's personal information and/or server's internal
Mar 10, 20217.524NONO
Improper access control vulnerability in GROWI prior to v5.1.4 (v5 series) and versions prior to v4.5.25 (v4 series) allows a remote authenticated attacker to bypass access restric
Oct 24, 20226.523NONO
In WESEEK GROWI before 3.5.0, a remote attacker can obtain the password hash of the creator of a page by leveraging wiki access to make API calls for page metadata. In other words,
Jul 9, 20197.523NONO
In WESEEK GROWI before 3.5.0, the site-wide basic authentication can be bypassed by adding a URL parameter access_token (this is the parameter used by the API). No valid token is r
Jul 9, 20197.523NONO
Weak Password Requirements in GitHub repository weseek/growi prior to v5.0.0.
Apr 5, 20226.522NONO
Improper authentication vulnerability in GROWI versions prior to v4.2.20 allows a remote attacker to view the unauthorized pages without access privileges via unspecified vectors.
Jun 22, 20216.522NONO

Exploit Exposure

Signals from CVEs in this product scope (43 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (43 CVEs).

Media Mentions

Signals from CVEs in this product scope (43 CVEs).

Top CNAs Publishing CVEs For Growi

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
4.2.217.21.8%00