CVE-2026-71236
Grocy's API request-body parser vulnerability allows for stored XSS attacks. Affected product deployments may be vulnerable if they use Grocy's API-writable fields without proper sanitization. Organizations using Grocy should prioritize patching to prevent potential XSS attacks. The CVE record indicates a high-severity vulnerability, but details about affected versions and patches are not provided. To ver [truncated]