chiprook
← Security
SecurityOctober 10, 2026, 00:40

GROWI 7.5.5 fixes CVE-2026-100727 unauthenticated file read

GROWI 7.5.5, released October 5, 2026, patches CVE-2026-100727, an access-control flaw letting unauthenticated visitors read files from non-public pages. Only deployments using the local upload backend are affected; CVSS 4.0 score is 6.9, CVSS 3.0 is 5.3.

GROWI 7.5.5 fixes CVE-2026-100727 unauthenticated file read
#GROWI
Read next
Security

Joomla extensions hit by two unauthenticated file upload flaws

Security

Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files

Security

WordPress Click2Shell: unauthenticated RCE, fixed in 7.1.1

Security

Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data