CVE-2025-43880: Medium severity GROWI GROWI vulnerability
Published Jun 25, 2025
·Updated
Inefficient regular expression complexity issue exists in GROWI prior to v7.1.6. If exploited, a logged-in user may cause a denial of service (DoS) condition.
Affected Software
1 affected component
GROWI GROWI<7.1.6
Event History
Jun 25, 2025
CVE Published
via MITRE·05:31 AM
Data Sourced
via MITRE·05:31 AM
DescriptionSeverity
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeakness
Sep 22, 57451
Event
via NVD·07:16 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-43880?
CVE-2025-43880 has been rated as high severity due to its potential to cause a denial of service (DoS) condition.
2
How do I fix CVE-2025-43880?
To fix CVE-2025-43880, upgrade GROWI to version 7.1.6 or later.
3
Who is affected by CVE-2025-43880?
Users of GROWI versions prior to 7.1.6 are affected by CVE-2025-43880.
4
What causes the issue in CVE-2025-43880?
CVE-2025-43880 is caused by an inefficient regular expression complexity issue in GROWI.
5
Can CVE-2025-43880 be exploited by unauthenticated users?
No, exploitation of CVE-2025-43880 requires a logged-in user.