Search
Search Results (3 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2024-55075 | 1 Grocy Project | 1 Grocy | 2025-09-29 | 4.3 Medium |
| Grocy through 4.3.0 allows remote attackers to obtain sensitive information via direct requests to pages that are not shown in the UI, such as calendar and recipes. | ||||
| CVE-2024-55076 | 1 Grocy Project | 1 Grocy | 2025-09-05 | 8.1 High |
| Grocy through 4.3.0 has no CSRF protection, as demonstrated by changing the Administrator's password. | ||||
| CVE-2024-55074 | 1 Grocy Project | 1 Grocy | 2025-09-05 | 8.8 High |
| The edit profile function of Grocy through 4.3.0 allows stored XSS and resultant privilege escalation by uploading a crafted HTML or SVG file, a different issue than CVE-2024-8370. | ||||
Page 1 of 1.