Junglewise Threat Intelligence

CVE-2026-26291: GROWI Stored Cross-Site Scripting

CVE-2026-26291 · Severity: medium · CVSS 5.4 · Published 2026-04-15

Technologies: GROWI, Inc. GROWI.

Executive brief

GROWI, a collaborative wiki and knowledge-sharing platform, contains a security flaw that allows an attacker to inject malicious scripts into shared pages. If a user views a compromised page, the script can execute in their browser, potentially leading to unauthorized actions or the theft of sensitive session information. This risk is particularly relevant for internal documentation sites where multiple users contribute content.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in GROWI versions up to and including v7.4.6. The flaw is rooted in improper neutralization of user-supplied input (CWE-79) during web page generation. An authenticated attacker with low privileges can inject malicious scripts into persistent data stores (such as wiki pages). When other users, including administrators, view the affected content, the script executes within the context of their session. This can lead to session hijacking, unauthorized data modification, or redirection to malicious sites. The vulnerability is addressed in GROWI v7.4.7.

Affected products

  • GROWI, Inc. GROWI v7.4.6 and earlier

Timeline

  • 2026-04-15: disclosed: Vulnerability reported via JVN/JPCERT/CC
  • 2026-04-15: advisory
  • 2026-04-15: patched: GROWI v7.4.7 released to address the issue

References