CVE-2026-41951 – GROWI EJS Template Injection

CVE ID :CVE-2026-41951

Published : May 11, 2026, 10:16 a.m. | 14 minutes ago

Description :Path traversal vulnerability exists in GROWI v7.5.0 and earlier, which may allow an attacker to execute arbitrary EJS templates on the server when an email server is running in GROWI.

Severity: 8.6 | HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more…