CVE-2026-26291: Growi, Inc Growi
Medium severity, CVSS 4.8. EPSS: 0.2% chance of exploitation in the next 30 days.
Stored cross-site scripting vulnerability exists in GROWI v7.4.6 and earlier. If this vulnerability is exploited, an arbitrary script may be executed in a user's web browser.
Affected products
- Growi, Inc Growi: up to and including v7.4.6
Published 2026-04-15. Last modified 2026-06-17.