Vulnerabilities > Grocy Project

DATE CVE VULNERABILITY TITLE RISK
2023-12-04 CVE-2023-48866 Cross-site Scripting vulnerability in Grocy Project Grocy
A Cross-Site Scripting (XSS) vulnerability in the recipe preparation component within /api/objects/recipes and note component within /api/objects/shopping_lists/ of Grocy <= 4.0.3 allows attackers to obtain the victim's cookies.
network
low complexity
grocy-project CWE-79
5.4
2023-11-15 CVE-2023-48197 Cross-site Scripting vulnerability in Grocy Project Grocy 4.0.3
Cross-Site Scripting (XSS) vulnerability in the ‘manageApiKeys’ component of Grocy 4.0.3 and earlier allows attackers to obtain victim's cookies when the victim clicks on the "see QR code" function.
network
low complexity
grocy-project CWE-79
5.4
2023-11-15 CVE-2023-48198 Cross-site Scripting vulnerability in Grocy Project Grocy 4.0.3
A Cross-Site Scripting (XSS) vulnerability in the 'product description' component within '/api/stock/products' of Grocy version <= 4.0.3 allows attackers to obtain a victim's cookies.
network
low complexity
grocy-project CWE-79
5.4
2023-11-15 CVE-2023-48199 Injection vulnerability in Grocy Project Grocy 4.0.3
HTML Injection vulnerability in the 'manageApiKeys' component in Grocy <= 4.0.3 allows attackers to inject arbitrary HTML content without script execution.
local
low complexity
grocy-project CWE-74
7.8
2023-11-15 CVE-2023-48200 Cross-site Scripting vulnerability in Grocy Project Grocy 4.0.3
Cross Site Scripting vulnerability in Grocy v.4.0.3 allows a local attacker to execute arbitrary code and obtain sensitive information via the equipment description component within /equipment/ component.
network
low complexity
grocy-project CWE-79
5.4
2023-09-15 CVE-2023-42270 Cross-Site Request Forgery (CSRF) vulnerability in Grocy Project Grocy
Grocy <= 4.0.2 is vulnerable to Cross Site Request Forgery (CSRF).
network
low complexity
grocy-project CWE-352
8.8
2020-11-18 CVE-2020-25454 Cross-site Scripting vulnerability in Grocy Project Grocy 2.7.1
Cross-site Scripting (XSS) vulnerability in grocy 2.7.1 via the add recipe module, which gets executed when deleting the recipe.
network
low complexity
grocy-project CWE-79
5.4