All 42 CVE vulnerabilities found in GROWI, with AI-generated Chinese analysis, references, and POCs.
This page documents common vulnerabilities associated with GROWI, an open-source wiki and knowledge management platform developed by Security First Japan. It aggregates security advisories and vulnerability reports specifically affecting this product, providing a centralized resource for users and security professionals to assess potential risks. The collected data covers a broad range of Common Weakness Enumerations (CWE) types, including cross-site scripting, path traversal, and information disclosure flaws, spanning from the product's early releases through recent updates. By consolidating these records, the page allows users to track vendor advisories and monitor how the developer addresses identified security issues over time. Readers can explore specific weakness classes to understand the nature of each flaw and its potential impact on system integrity. Additionally, the historical data enables users to look up a product's vulnerability history, offering insights into the stability and security maturity of GROWI across different versions. This comprehensive overview helps administrators make informed decisions about patching, upgrading, and configuring their instances to mitigate known threats. The content is sourced from official vendor announcements, third-party security databases, and community reports, ensuring a thorough reflection of the threat landscape. Whether you are a developer maintaining the software or an end-user relying on it for organizational knowledge, this page serves as a critical reference for understanding and managing security risks. All listed vulnerabilities are documented with their respective identifiers, release dates, and affected versions to facilitate accurate tracking and remediation efforts without requiring speculative analysis or external verification.
Vendor: WESEEK, Inc.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2020-5682 | Weseek GROWI 输入验证错误漏洞 | 5.3 | - | 2020-12-16 |
| CVE-2020-5678 | WESEEK GROWI 跨站脚本漏洞 | 5.4 | - | 2020-12-03 |
| CVE-2020-5677 | WESEEK GROWI 跨站脚本漏洞 | 6.1 | - | 2020-12-03 |
| CVE-2020-5676 | WESEEK GROWI 信息泄露漏洞 | 5.3 | - | 2020-12-03 |
| CVE-2019-5969 | WESEEK GROWI 输入验证错误漏洞 | 6.1 | - | 2019-07-05 |
| CVE-2019-5968 | WESEEK GROWI 跨站请求伪造漏洞 | 8.8 | - | 2019-07-05 |
| CVE-2018-16205 | WESEEK GROWI 跨站脚本漏洞 | 5.4 | - | 2019-01-09 |
| CVE-2018-0698 | WESEEK GROWI 跨站脚本漏洞 | 6.1 | - | 2019-01-09 |
| CVE-2018-0652 | WESEEK GROWI 跨站脚本漏洞 | 4.8 | - | 2018-09-07 |
| CVE-2018-0655 | WESEEK GROWI 跨站脚本漏洞 | 4.8 | - | 2018-09-07 |
| CVE-2018-0654 | WESEEK GROWI 跨站脚本漏洞 | 6.1 | - | 2018-09-07 |
| CVE-2018-0653 | WESEEK GROWI 跨站脚本漏洞 | 6.1 | - | 2018-09-07 |
All 42 known CVE vulnerabilities affecting GROWI with full Chinese analysis, references, and POCs where available.