Skip to content
Noroxi

gridea records

2 published records for vendor gridea.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
0%
Median publish → KEV
No record has entered KEV

Records by year

  1. 19
  2. 22

Bar: total · dark part: CISA KEV.

Attack profile

All records

2 records
  • Gridea version 0.9.3 allows an external attacker to execute arbitrary code remotely on any client attempting to view a malicious markdown fi

    HighCVSS 7.8No exploitEPSS 0%

    gridea · grideaSep 30, 2022

  • Gridea v0.8.0 has an XSS vulnerability through which the Nodejs module can be called to achieve arbitrary code execution, as demonstrated by

    MediumCVSS 6.1No exploitEPSS 1%

    gridea · grideaMay 13, 2019