CVE-2019-13338: Weseek Growi

High severity, CVSS 7.5. EPSS: 1.8% chance of exploitation in the next 30 days.

In WESEEK GROWI before 3.5.0, a remote attacker can obtain the password hash of the creator of a page by leveraging wiki access to make API calls for page metadata. In other words, the password hash can be retrieved even though it is not a publicly available field.

Affected products

  • Weseek Growi: before 3.5.0 (fixed in 3.5.0)

Published 2019-07-09. Last modified 2026-06-17.