Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Grocy Project

11 known vulnerabilities

4
HIGH
6
MEDIUM
1
LOW

Top Products

grocy 11
11 CVEs
8.1
CVE-2024-55076

Grocy through 4.3.0 has no CSRF protection, as demonstrated by changing the Administrator's password.

4.3
CVE-2024-55075

Grocy through 4.3.0 allows remote attackers to obtain sensitive information via direct requests to pages that are not sh

8.8
CVE-2024-55074

The edit profile function of Grocy through 4.3.0 allows stored XSS and resultant privilege escalation by uploading a cra

3.5
CVE-2024-8370

A vulnerability classified as problematic was found in Grocy up to 4.2.0. This vulnerability affects unknown code of the

5.4
CVE-2023-48866

A Cross-Site Scripting (XSS) vulnerability in the recipe preparation component within /api/objects/recipes and note comp

5.4
CVE-2023-48200

Cross Site Scripting vulnerability in Grocy v.4.0.3 allows a local attacker to execute arbitrary code and obtain sensiti

7.8
CVE-2023-48199

HTML Injection vulnerability in the 'manageApiKeys' component in Grocy <= 4.0.3 allows attackers to inject arbitrary HTM

5.4
CVE-2023-48198

A Cross-Site Scripting (XSS) vulnerability in the 'product description' component within '/api/stock/products' of Grocy

5.4
CVE-2023-48197

Cross-Site Scripting (XSS) vulnerability in the ‘manageApiKeys’ component of Grocy 4.0.3 and earlier allows attackers to

8.8
CVE-2023-42270

Grocy <= 4.0.2 is vulnerable to Cross Site Request Forgery (CSRF).

5.4
CVE-2020-25454

Cross-site Scripting (XSS) vulnerability in grocy 2.7.1 via the add recipe module, which gets executed when deleting the

Frequently Asked Questions

How many CVEs affect Grocy Project?

Grocy Project has 11 CVE records in our database, including 0 critical and 4 high severity vulnerabilities.

What are the most severe Grocy Project vulnerabilities?

Grocy Project has 0 critical severity (CVSS 9.0+) and 4 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.

How can I scan for Grocy Project vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Grocy Project products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Grocy Project Vulnerabilities

CyberStrike scans your infrastructure for Grocy Project vulnerabilities and provides real-time remediation guidance.

Get Started