CVE-2023-46699: Weseek Growi

Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.

Cross-site request forgery (CSRF) vulnerability exists in the User settings (/me) page of GROWI versions prior to v6.0.0. If a user views a malicious page while logging in, settings may be changed without the user's intention.

Affected products

  • Weseek Growi: before 6.0.0 (fixed in 6.0.0)

Published 2023-12-26. Last modified 2026-06-17.