VYPR
Vendor

Growilabs

Products
1
CVEs
3
Across products
3
Status
Private

Products

1

Recent CVEs

3
  • CVE-2026-80191HigAug 26, 2026
    risk 0.42cvss 7.5epss 0.00

    GROWI applies its page-viewer permission check to attachment requests only when the request carries an authenticated user. retrieveAttachmentFromIdParam in apps/app/src/server/routes/attachment/get.ts guards the check with a condition requiring the user to be non-null, so a…

  • CVE-2026-84205MedSep 1, 2026
    risk 0.35cvss 6.5epss 0.00

    GROWI contains an access control vulnerability in the GET /_api/v3/revisions/:id endpoint that validates access against a query parameter but returns the revision identified by the path parameter without confirming they reference the same page. Authenticated attackers can pair a…

  • CVE-2026-84204MedSep 1, 2026
    risk 0.35cvss 6.5epss 0.00

    GROWI contains an access control vulnerability in the GET /_api/v3/attachment/:id endpoint that fails to validate page access permissions. Authenticated attackers can retrieve attachment metadata from pages they cannot view by supplying known attachment identifiers.