VendorsGrocy Projectgrocyall versions
Vulnerabilities

Grocy Project Grocy

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

11CVEs
CVE-2024-55074
The edit profile function of Grocy through 4.3.0 allows stored XSS and resultant privilege escalation by uploading a crafted HTML or SVG file, a different issue than CVE-2024-8370.
Published 2025-01-06 · Analyzed
9.0EPSS 0.007
CVE-2023-42270
Grocy <= 4.0.2 is vulnerable to Cross Site Request Forgery (CSRF).
Published 2023-09-15 · Modified
8.8EPSS 0.004
CVE-2024-55076
Grocy through 4.3.0 has no CSRF protection, as demonstrated by changing the Administrator's password.
Published 2025-01-06 · Analyzed
8.1EPSS 0.003
CVE-2023-48199
HTML Injection vulnerability in the 'manageApiKeys' component in Grocy <= 4.0.3 allows attackers to inject arbitrary HTML content without script execution. This occurs when user-supplied data is not appropriately sanitized, enabling the injection of HTML tags through parameter values. The attacker can then manipulate page content in the QR code detail popup, often coupled with social engineering tactics, exploiting both the trust of users and the application's lack of proper input handling.
Published 2023-11-15 · Modified
7.8EPSS 0.005
CVE-2023-48200
Cross Site Scripting vulnerability in Grocy v.4.0.3 allows a local attacker to execute arbitrary code and obtain sensitive information via the equipment description component within /equipment/ component.
Published 2023-11-15 · Modified
5.4EPSS 0.008
CVE-2020-25454
Cross-site Scripting (XSS) vulnerability in grocy 2.7.1 via the add recipe module, which gets executed when deleting the recipe.
Published 2020-11-18 · Modified
5.4EPSS 0.007
CVE-2023-48866
A Cross-Site Scripting (XSS) vulnerability in the recipe preparation component within /api/objects/recipes and note component within /api/objects/shopping_lists/ of Grocy <= 4.0.3 allows attackers to obtain the victim's cookies.
Published 2023-12-04 · Modified
5.4EPSS 0.007
CVE-2023-48198
A Cross-Site Scripting (XSS) vulnerability in the 'product description' component within '/api/stock/products' of Grocy version <= 4.0.3 allows attackers to obtain a victim's cookies.
Published 2023-11-15 · Modified
5.4EPSS 0.007
CVE-2023-48197
Cross-Site Scripting (XSS) vulnerability in the ‘manageApiKeys’ component of Grocy 4.0.3 and earlier allows attackers to obtain victim's cookies when the victim clicks on the "see QR code" function.
Published 2023-11-15 · Modified
5.4EPSS 0.007
CVE-2024-8370
Grocy SVG File Upload recipepictures cross site scripting
Published 2024-09-01 · Analyzed
5.4EPSS 0.004
CVE-2024-55075
Grocy through 4.3.0 allows remote attackers to obtain sensitive information via direct requests to pages that are not shown in the UI, such as calendar and recipes.
Published 2025-01-06 · Analyzed
5.3EPSS 0.005