Requarks

Wiki.Js

19 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.25%
  • Veröffentlicht 16.09.2026 20:32:36
  • Zuletzt bearbeitet 24.09.2026 21:08:22

Wiki.js through 2.5.314 fails to require path separators when matching START and END page rules, allowing attackers to access pages sharing a prefix with authorized folders. Users granted access to a folder can read and modify unrelated pages with ma...

Exploit
  • EPSS 0.3%
  • Veröffentlicht 16.09.2026 20:32:35
  • Zuletzt bearbeitet 24.09.2026 21:08:22

Wiki.js through 2.5.314 contains a server-side request forgery vulnerability in the Image Prefetch renderer that fetches arbitrary URLs without protocol, host, or address validation. Attackers with page editing permissions can inject img elements wit...

Exploit
  • EPSS 0.35%
  • Veröffentlicht 16.09.2026 20:32:34
  • Zuletzt bearbeitet 24.09.2026 20:47:31

Wiki.js through 2.5.314 omits page tags from authorization checks in multiple GraphQL resolvers, allowing tag-based access restrictions to be bypassed. Attackers can query the list, tree, tags, searchTags, and links resolvers to retrieve restricted p...

Exploit
  • EPSS 0.38%
  • Veröffentlicht 12.05.2026 20:33:53
  • Zuletzt bearbeitet 14.05.2026 14:56:13

Wiki.js is an open source wiki app built on Node.js. Prior to 2.5.313, the users.update GraphQL mutation accepts an arbitrary groups array and applies it directly to the database with no validation of the group IDs supplied. The resolver passes the c...

  • EPSS 0.36%
  • Veröffentlicht 18.11.2025 00:00:00
  • Zuletzt bearbeitet 31.12.2025 02:06:51

Requarks Wiki.js 2.5.307 does not properly revoke or invalidate active JWT tokens when a user logs out. As a result, previously issued tokens remain valid and can be reused to access the system, even after logout. This behavior affects session integr...

  • EPSS 0.4%
  • Veröffentlicht 18.09.2024 17:15:18
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Wiki.js is an open source wiki app built on Node.js. A disabled user can still gain access to a wiki by abusing the password reset function. While setting up SMTP e-mail's on my server, I tested said e-mails by performing a password reset with my tes...

  • EPSS 0.4%
  • Veröffentlicht 20.05.2024 22:15:08
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Wiki.js is al wiki app built on Node.js. Client side template injection was discovered, that could allow an attacker to inject malicious JavaScript into the content section of pages that would execute once a victim loads the page that contains the pa...

Exploit
  • EPSS 1.95%
  • Veröffentlicht 12.05.2022 08:15:07
  • Zuletzt bearbeitet 21.11.2024 06:41:14

Authentication Bypass Using an Alternate Path or Channel in GitHub repository requarks/wiki prior to 2.5.281. User can get root user permissions

  • EPSS 0.72%
  • Veröffentlicht 22.02.2022 20:15:07
  • Zuletzt bearbeitet 21.11.2024 06:49:01

Wiki.js is a wiki app built on Node.js. In affected versions an authenticated user with write access on a restricted set of paths can update a page outside the allowed paths by specifying a different target page ID while keeping the path intact. The ...

Exploit
  • EPSS 0.62%
  • Veröffentlicht 29.12.2021 17:15:07
  • Zuletzt bearbeitet 21.11.2024 05:55:45

In Requarks wiki.js, versions 2.0.0-beta.147 to 2.5.255 are affected by Stored XSS vulnerability, where a low privileged (editor) user can upload a SVG file that contains malicious JavaScript while uploading assets in the page. That will send the JWT...