CVE-2026-71236 | Grocy API Request-Body Parser BaseApiController.php GetParsedAndFilteredRequestBody cross site scripting
A vulnerability categorized as problematic has been discovered in Grocy. Affected by this issue is the function GetParsedAndFilteredRequestBody of the file controllers/Api/BaseApiController.php of the component API Request-Body Parser. Such manipulation leads to cross site scripting.
This vulnerability is documented as CVE-2026-71236. The attack can be executed remotely. There is not any exploit available.VulDB Recent EntriesRead More