VYPR
Medium severity6.1NVD Advisory· Published Sep 21, 2021· Updated Jun 17, 2026

CVE-2021-20829

CVE-2021-20829

Description

Cross-site scripting vulnerability due to the inadequate tag sanitization in GROWI versions v4.2.19 and earlier allows remote attackers to execute an arbitrary script on the web browser of the user who accesses a specially crafted page.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Weseek/Growi2 versions
    cpe:2.3:a:weseek:growi:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:weseek:growi:*:*:*:*:*:*:*:*range: <=4.2.19
    • (no CPE)range: versions v4.2.19 and earlier
  • GROWI/GROWIllm-fuzzy
    Range: <=v4.2.19

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.