Vulnerabilities > Weseek > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-03-10 CVE-2021-20667 Cross-site Scripting vulnerability in Weseek Growi
Stored cross-site scripting vulnerability due to inadequate CSP (Content Security Policy) configuration in GROWI versions v4.2.2 and earlier allows remote authenticated attackers to inject an arbitrary script via a specially crafted content.
network
low complexity
weseek CWE-79
5.4
2021-01-19 CVE-2021-20619 Cross-site Scripting vulnerability in Weseek Growi 4.2.0/4.2.1/4.2.2
Cross-site scripting vulnerability in GROWI (v4.2 Series) versions prior to v4.2.3 allows remote attackers to inject an arbitrary script via unspecified vectors.
network
low complexity
weseek CWE-79
6.1
2020-12-03 CVE-2020-5678 Cross-site Scripting vulnerability in Weseek Growi
Stored cross-site scripting vulnerability in GROWI v3.8.1 and earlier allows remote attackers to inject arbitrary script via unspecified vectors.
network
low complexity
weseek CWE-79
6.1
2020-12-03 CVE-2020-5677 Cross-site Scripting vulnerability in Weseek Growi
Reflected cross-site scripting vulnerability in GROWI v4.0.0 and earlier allows remote attackers to inject arbitrary script via unspecified vectors.
network
low complexity
weseek CWE-79
6.1
2019-07-05 CVE-2019-5969 Open Redirect vulnerability in Weseek Growi
Open redirect vulnerability in GROWI v3.4.6 and earlier allows remote attackersto redirect users to arbitrary web sites and conduct phishing attacks via the process of login.
network
low complexity
weseek CWE-601
6.1
2019-01-09 CVE-2018-16205 Cross-site Scripting vulnerability in Weseek Growi
Cross-site scripting vulnerability in GROWI v3.2.3 and earlier allows remote attackers to inject arbitrary web script or HTML via New Page modal.
network
low complexity
weseek CWE-79
5.4
2019-01-09 CVE-2018-0698 Cross-site Scripting vulnerability in Weseek Growi
Cross-site scripting vulnerability in GROWI v3.2.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
low complexity
weseek CWE-79
5.4
2018-09-07 CVE-2018-0655 Cross-site Scripting vulnerability in Weseek Growi
Cross-site scripting vulnerability in GROWI v.3.1.11 and earlier allows remote authenticated attackers to inject arbitrary web script or HTML via the app settings section of admin page.
network
low complexity
weseek CWE-79
4.8
2018-09-07 CVE-2018-0654 Cross-site Scripting vulnerability in Weseek Growi
Cross-site scripting vulnerability in GROWI v.3.1.11 and earlier allows remote attackers to inject arbitrary web script or HTML via the modal for creating Wiki page.
network
low complexity
weseek CWE-79
6.1
2018-09-07 CVE-2018-0653 Cross-site Scripting vulnerability in Weseek Growi
Cross-site scripting vulnerability in GROWI v.3.1.11 and earlier allows remote attackers to inject arbitrary web script or HTML via Wiki page view.
network
low complexity
weseek CWE-79
6.1