CVE-2025-61994: XSS
Published Nov 6, 2025
·Updated
Cross-site scripting vulnerability exists in GROWI prior to v7.2.10. If a malicious user creates a page containing crafted contents, an arbitrary script may be executed on the web browser of a victim user who accesses the page.
Affected Software
1 affected component
GROWI GROWI<7.2.10
Event History
Nov 6, 2025
CVE Published
via MITRE·04:14 AM
Data Sourced
via MITRE·04:14 AM
DescriptionSeverity
Data Sourced
via NVD·05:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-61994?
CVE-2025-61994 is considered a high severity vulnerability due to its potential for executing arbitrary scripts in user browsers.
2
How do I fix CVE-2025-61994?
To fix CVE-2025-61994, upgrade GROWI to version 7.2.10 or later.
3
What impact does CVE-2025-61994 have on users?
CVE-2025-61994 allows attackers to execute scripts in the browser of users who access the crafted page, compromising their session and data.
4
Who is affected by CVE-2025-61994?
CVE-2025-61994 affects all versions of GROWI prior to v7.2.10.
5
Can CVE-2025-61994 be exploited easily?
Yes, CVE-2025-61994 can be exploited easily if a user visits a page containing crafted content by a malicious actor.