Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/growi/growi

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

GROWI contains an access control vulnerability in the GET /_api/v3/revisions/:id endpoint that validates access against a query parameter but returns the revision identified by the path parameter without confirming they reference the same page. Authenticated attackers can pair a page identifier they can access with an arbitrary revision identifier to read revision content from pages they lack permission to view.

Join the discussion

GROWI contains an access control vulnerability in the GET /_api/v3/attachment/:id endpoint that fails to validate page access permissions. Authenticated attackers can retrieve attachment metadata from pages they cannot view by supplying known attachment identifiers.

Join the discussion

GROWI versions prior to 8.0.2 have a missing authorization check for attachment requests when the request is unauthenticated. This allows an unauthenticated attacker with knowledge of an attachment identifier to retrieve files regardless of page privacy or permission settings. Version 8.0.2 fixes this by enforcing permission checks for both authenticated and unauthenticated requests, except when a valid share link is used.

Join the discussion

A path traversal vulnerability (CVE-2026-41951) exists in GROWI version 7.5.0 and earlier. This vulnerability may allow an attacker to execute arbitrary EJS templates on the server when the email server feature is enabled in GROWI. The vulnerability has a high severity rating with a CVSS score of 7.2. No official patch or remediation guidance is currently provided by the vendor. Exploitation in the wild is not known at this time.

Join the discussion

GROWI, Inc. 's GROWI product version 7.5.0 and earlier contains a vulnerability due to inefficient regular expression complexity, which can be exploited via crafted input strings to cause a denial of service. This vulnerability is classified as a regular expression denial of service (ReDoS). The CVSS v3.0 score is 7.5, indicating a high severity impact primarily affecting availability. There is no information about an official patch or remediation level from the vendor, and no known exploits are reported in the wild. The vulnerability requires no privileges and no user interaction to exploit over the network.

Join the discussion

GROWI version 7.4.6 and earlier contain a stored cross-site scripting (XSS) vulnerability that allows execution of arbitrary scripts in a user's browser if exploited. This vulnerability has a medium severity rating with a CVSS score of 5.4. No official patch or remediation guidance is currently available from the vendor. There are no known exploits in the wild at this time.

Join the discussion

GROWI OpenAI thread/message API endpoints do not perform authorization. Affected are v7.4.5 and earlier versions. A logged-in user who knows a shared AI assistant's identifier may view and/or tamper the other user's threads/messages.

Join the discussion

Cross-site request forgery vulnerability exists in GROWI v7.3.3 and earlier. If a user views a malicious page while logged in, the user may be tricked to do unintended operations.

Join the discussion

Cross-site scripting vulnerability exists in GROWI prior to v7.2.10. If a malicious user creates a page containing crafted contents, an arbitrary script may be executed on the web browser of a victim user who accesses the page.

Join the discussion

GROWI v4.2.7 and earlier contains a cross-site scripting vulnerability in the page alert function. If a user accesses a crafted URL while logged in to the affected product, an arbitrary script may be executed on the user's web browser.

Join the discussion

Showing 1 to 10 of 10 results

Filters:Package: pkg:github/growi/growi
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses