Vulnerabilities > Gridea

DATE CVE VULNERABILITY TITLE RISK
2022-09-30 CVE-2022-40274 Unspecified vulnerability in Gridea 0.9.3
Gridea version 0.9.3 allows an external attacker to execute arbitrary code remotely on any client attempting to view a malicious markdown file through Gridea.
local
low complexity
gridea
7.8
2019-05-13 CVE-2019-12047 Cross-site Scripting vulnerability in Gridea 0.8.0
Gridea v0.8.0 has an XSS vulnerability through which the Nodejs module can be called to achieve arbitrary code execution, as demonstrated by child_process.exec and the "<img src=# onerror='eval(new Buffer(" substring.
network
low complexity
gridea CWE-79
6.1