
CVE-2026-26291 Stored cross-site scripting vulnerability exists in GROWI v7.4.6 and earlier. If this vulnerability is exploited, an arbitrary script may be executed in a user's web … https://www.cve.org/CVERecord?id=CVE-2026-26291
Post summary
The text announces a stored XSS flaw in GROWI v7.4.6 and earlier, highlighting its potential for arbitrary script execution, but does not mention PoC, exploits, patches, or active exploitation.
