These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-100727 is an improper access control vulnerability in GROWI that allows unauthenticated attackers to read files in non-public pages when the file upload setting is configured as 'Local'. The vulnerability exists due to inadequate access controls, allowing unauthorized file access. Defenders responsible for GROWI instances should assess exposure and implement compensating controls to restrict file [truncated]
CVE-2026-68951 is an incorrect authorization vulnerability in GROWI that allows unauthenticated attackers to retrieve user bookmark data. This vulnerability has a CVSS score of 6.9 and MEDIUM severity. The CVE record was published on 2026-08-31T07:17:45.400Z and has not been modified since then. Users of GROWI, administrators of GROWI installations, and security teams should verify GROWI installations and [truncated]
The GROWI application, specifically version(s) [insert versions if available], contains a vulnerability with an authorization bypass through a user-controlled key in the bookmark folder APIs. This allows an authenticated attacker to retrieve, tamper with, and/or delete the other user's bookmark data. Administrators and users of GROWI installations should be aware of this vulnerability and take necessary a [truncated]
GROWI, an open-source wiki platform developed by GROWI, Inc., is affected by a regular expression denial of service (ReDoS) vulnerability. The flaw stems from improper handling of crafted input strings that can trigger catastrophic backtracking in vulnerable regex patterns, leading to resource exhaustion and service unavailability. The vulnerability is classified as CWE-1333 (Inefficient Regular Expressio [truncated]
A stored cross-site scripting (XSS) vulnerability affects GROWI v7.4.6 and earlier. If exploited, this flaw allows an attacker to execute arbitrary scripts in a user's web browser. The vulnerability was published on April 15, 2026, and last modified on May 19, 2026. The CVSS 4.0 score of 4.8 reflects a medium severity with network attack vector, low attack complexity, and required user interaction. The we [truncated]
CVE-2026-25083 is a HIGH severity authorization bypass vulnerability affecting GROWI wiki platform versions 7.4.5 and earlier. The vulnerability exists in OpenAI thread/message API endpoints that fail to enforce proper access controls. A logged-in attacker with knowledge of a shared AI assistant's identifier can view and modify other users' threads and messages without authorization. The CVSS 4.0 vector i [truncated]