CVE-2025-54806: XSS
Published Oct 23, 2025
·Updated
GROWI v4.2.7 and earlier contains a cross-site scripting vulnerability in the page alert function. If a user accesses a crafted URL while logged in to the affected product, an arbitrary script may be executed on the user's web browser.
Affected Software
2 affected components
GROWI GROWI<4.2.7
WESEEK GROWI<4.2.8
Event History
Oct 23, 2025
CVE Published
via MITRE·04:10 AM
Data Sourced
via MITRE·04:10 AM
DescriptionSeverity
Data Sourced
via NVD·05:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-54806?
CVE-2025-54806 is classified as a medium severity cross-site scripting vulnerability.
2
How do I fix CVE-2025-54806?
To fix CVE-2025-54806, you should update GROWI to version 4.2.8 or later.
3
Is my version vulnerable to CVE-2025-54806?
GROWI versions 4.2.7 and earlier are vulnerable to CVE-2025-54806.
4
What type of vulnerability is CVE-2025-54806?
CVE-2025-54806 is a cross-site scripting (XSS) vulnerability.
5
Can CVE-2025-54806 lead to data theft?
Yes, CVE-2025-54806 can potentially allow attackers to execute arbitrary scripts, leading to data theft.