Products

Showing 2 vulnerabilities on this page

Signals CISA KEV Ransomware Nuclei
grocy vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Grocy - Stored XSS via HTMLPurifier Output Double-Decode

Grocy's API request-body parser (controllers/Api/BaseApiController.php, GetParsedAndFilteredRequestBody) purifies incoming field values with HTMLPurifier, then manually reverses HTML-entity encoding of the resulting output by replacing &lt;, &gt;, and &amp; back to <, >, and & immediately after purification.

CWE-79Aug 5, 2026
CVSS8.7v3.1EPSS0.199%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Stored XSS in Grocy

Versions of Grocy <= 2.7.1 are vulnerable to Cross-Site Scripting via the Create Shopping List module, that is rendered upon deleting that Shopping List. The issue was also found in users, batteries, chores, equipment, locations, quantity units, shopping locations, tasks, taskcategories, product groups, recipes and products. Authentication is required to exploit these issues and Grocy should not be publicly exposed. The linked reference details a proof-of-concept.

CWE-79Oct 14, 2020
CVSS7.3v3.1EPSS1.25%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX