PatchSiren

grocy CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH grocy CVE published 2026-08-05

CVE-2026-71236

Grocy's API request-body parser vulnerability allows for stored XSS attacks. Affected product deployments may be vulnerable if they use Grocy's API-writable fields without proper sanitization. Organizations using Grocy should prioritize patching to prevent potential XSS attacks. The CVE record indicates a high-severity vulnerability, but details about affected versions and patches are not provided. To ver [truncated]

CRITICAL grocy CVE published 2026-06-15

CVE-2026-50890

A SQL injection vulnerability was discovered in grocy v4.6.0, specifically in the product-group parameter at /stockreports/spendings. This vulnerability, tracked as CVE-2026-50890, enables attackers to access sensitive database information by injecting malicious SQL statements.