CVE-2025-61994: Growi, Inc Growi
Medium severity, CVSS 4.8. EPSS: 0.2% chance of exploitation in the next 30 days.
Cross-site scripting vulnerability exists in GROWI prior to v7.2.10. If a malicious user creates a page containing crafted contents, an arbitrary script may be executed on the web browser of a victim user who accesses the page.
Affected products
- Growi, Inc Growi: before v7.2.10 (fixed in v7.2.10)
Published 2025-11-06. Last modified 2026-06-17.