CNNVD-202511-695 Information

CNNVD ID

CNNVD-202511-695

CVE-2025-61994

  • CNNVD Published: 2025-11-06

Description (Chinese)

Weseek Growi是日本Weseek公司的一个可以用Markdown编写的开源wiki系统。 Weseek Growi 7.2.10之前版本存在跨站脚本漏洞,该漏洞源于恶意用户创建包含特制内容的页面,可能导致跨站脚本攻击。

Description (English)

Weseek Growi is an open-source wiki system that Weseek, Japan, could use Markdown. There was a cross-site script loophole in the pre-Weseek Growi 7.2.10 version, which resulted from malicious users creating pages with special content that could lead to cross-site script attacks.

Hazard Level

High

Vulnerability Type

跨站脚本

Affected Vendor

Weseek

Published

2025-11-06

Last Modified

2026-02-24

References

https://growi.co.jp/news/39/ https://jvn.jp/en/jp/JVN95942191/

Patch

https://growi.org/en/

Share on: