CVE-2023-48866: Grocy Project Grocy
Medium severity, CVSS 5.4. EPSS: 0.7% chance of exploitation in the next 30 days.
A Cross-Site Scripting (XSS) vulnerability in the recipe preparation component within /api/objects/recipes and note component within /api/objects/shopping_lists/ of Grocy <= 4.0.3 allows attackers to obtain the victim's cookies.
Affected products
- Grocy Project Grocy: up to and including 4.0.3
Published 2023-12-04. Last modified 2026-06-17.