Vulnerabilities > Weseek > Growi > 1.2.16

DATE CVE VULNERABILITY TITLE RISK
2019-07-05 CVE-2019-5968 Cross-Site Request Forgery (CSRF) vulnerability in Weseek Growi
Cross-site request forgery (CSRF) vulnerability in GROWI v3.4.6 and earlier allows remote attackers to hijack the authentication of administrators via updating user's 'Basic Info'.
network
weseek CWE-352
6.8
2019-01-09 CVE-2018-16205 Cross-site Scripting vulnerability in Weseek Growi
Cross-site scripting vulnerability in GROWI v3.2.3 and earlier allows remote attackers to inject arbitrary web script or HTML via New Page modal.
network
weseek CWE-79
3.5
2019-01-09 CVE-2018-0698 Cross-site Scripting vulnerability in Weseek Growi
Cross-site scripting vulnerability in GROWI v3.2.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
weseek CWE-79
3.5
2018-09-07 CVE-2018-0655 Cross-site Scripting vulnerability in Weseek Growi
Cross-site scripting vulnerability in GROWI v.3.1.11 and earlier allows remote authenticated attackers to inject arbitrary web script or HTML via the app settings section of admin page.
network
weseek CWE-79
3.5
2018-09-07 CVE-2018-0654 Cross-site Scripting vulnerability in Weseek Growi
Cross-site scripting vulnerability in GROWI v.3.1.11 and earlier allows remote attackers to inject arbitrary web script or HTML via the modal for creating Wiki page.
network
weseek CWE-79
4.3
2018-09-07 CVE-2018-0653 Cross-site Scripting vulnerability in Weseek Growi
Cross-site scripting vulnerability in GROWI v.3.1.11 and earlier allows remote attackers to inject arbitrary web script or HTML via Wiki page view.
network
weseek CWE-79
4.3
2018-09-07 CVE-2018-0652 Cross-site Scripting vulnerability in Weseek Growi
Cross-site scripting vulnerability in GROWI v.3.1.11 and earlier allows remote authenticated attackers to inject arbitrary web script or HTML via the UserGroup Management section of admin page.
network
weseek CWE-79
3.5