CVE-2026-26291: Growi, Inc Growi

Medium severity, CVSS 4.8. EPSS: 0.2% chance of exploitation in the next 30 days.

Stored cross-site scripting vulnerability exists in GROWI v7.4.6 and earlier. If this vulnerability is exploited, an arbitrary script may be executed in a user's web browser.

Affected products

Published 2026-04-15. Last modified 2026-06-17.