📦 Growi

by Weseek

🔍 What is Growi?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2021-20736

CRITICAL CVSS 9.1 Jun 22, 2021

This NoSQL injection vulnerability in GROWI wiki software allows attackers to manipulate database queries and access/modify stored data. It affects GROWI versions before v4.2.20, potentially compromis...

CVE-2021-20670

HIGH CVSS 7.5 Mar 10, 2021

CVE-2021-20670 is an improper access control vulnerability in GROWI wiki software that allows unauthenticated remote attackers to read user personal information and server internal data. This affects ...

CVE-2025-54806

MEDIUM CVSS 6.1 Oct 23, 2025

GROWI v4.2.7 and earlier contains a stored cross-site scripting vulnerability in the page alert function. Attackers can craft malicious URLs that execute arbitrary JavaScript in victims' browsers when...