VendorsGrocy Projectgrocyany version
Vulnerabilities

Grocy Project Grocy any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2024-55074
The edit profile function of Grocy through 4.3.0 allows stored XSS and resultant privilege escalation by uploading a crafted HTML or SVG file, a different issue than CVE-2024-8370.
Published 2025-01-06 · Analyzed
9.0EPSS 0.007
CVE-2023-42270
Grocy <= 4.0.2 is vulnerable to Cross Site Request Forgery (CSRF).
Published 2023-09-15 · Modified
8.8EPSS 0.004
CVE-2024-55076
Grocy through 4.3.0 has no CSRF protection, as demonstrated by changing the Administrator's password.
Published 2025-01-06 · Analyzed
8.1EPSS 0.003
CVE-2023-48866
A Cross-Site Scripting (XSS) vulnerability in the recipe preparation component within /api/objects/recipes and note component within /api/objects/shopping_lists/ of Grocy <= 4.0.3 allows attackers to obtain the victim's cookies.
Published 2023-12-04 · Modified
5.4EPSS 0.007
CVE-2024-8370
Grocy SVG File Upload recipepictures cross site scripting
Published 2024-09-01 · Analyzed
5.4EPSS 0.004
CVE-2024-55075
Grocy through 4.3.0 allows remote attackers to obtain sensitive information via direct requests to pages that are not shown in the UI, such as calendar and recipes.
Published 2025-01-06 · Analyzed
5.3EPSS 0.005