CVE-2026-41951
Severity CVSS v4.0:
HIGH
Type:
CWE-22
Path Traversal
Publication date:
11/05/2026
Last modified:
11/05/2026
Description
Path traversal vulnerability exists in GROWI v7.5.0 and earlier, which may allow an attacker to execute arbitrary EJS templates on the server when an email server is running in GROWI.
Impact
Base Score 4.0
8.60
Severity 4.0
HIGH
Base Score 3.x
7.20
Severity 3.x
HIGH



