CVE-2025-68663
- EPSS 0.05%
- Veröffentlicht 11.02.2026 20:29:40
- Zuletzt bearbeitet 20.02.2026 18:14:25
Outline is a service that allows for collaborative documentation. Prior to 1.1.0, a vulnerability was found in Outline's WebSocket authentication mechanism that allows suspended users to maintain or establish real-time WebSocket connections and conti...
CVE-2025-64487
- EPSS 0.01%
- Veröffentlicht 11.02.2026 20:25:41
- Zuletzt bearbeitet 20.02.2026 18:17:53
Outline is a service that allows for collaborative documentation. Prior to 1.1.0, a privilege escalation vulnerability exists in the Outline document management system due to inconsistent authorization checks between user and group membership managem...
CVE-2026-25062
- EPSS 0.03%
- Veröffentlicht 11.02.2026 20:23:07
- Zuletzt bearbeitet 20.02.2026 18:10:18
Outline is a service that allows for collaborative documentation. Prior to 1.4.0, during the JSON import process, the value of attachments[].key from the imported JSON is passed directly to path.join(rootPath, node.key) and then read using fs.readFil...
CVE-2023-54331
- EPSS 0.01%
- Veröffentlicht 13.01.2026 22:52:06
- Zuletzt bearbeitet 02.02.2026 16:16:17
Outline 1.6.0 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted service path in the OutlineService executable to injec...
CVE-2025-58351
- EPSS 0.03%
- Veröffentlicht 03.09.2025 03:20:54
- Zuletzt bearbeitet 20.10.2025 18:46:57
Outline is a service that allows for collaborative documentation. In versions 0.72.0 through 0.83.0, Outline introduced a feature which facilitates local file system storage capabilities as an optional file storage strategy. This feature allowed a CS...
CVE-2024-40626
- EPSS 0.23%
- Veröffentlicht 16.07.2024 17:15:11
- Zuletzt bearbeitet 10.10.2025 15:30:01
Outline is an open source, collaborative document editor. A type confusion issue was found in ProseMirror’s rendering process that leads to a Stored Cross-Site Scripting (XSS) vulnerability in Outline. An authenticated user can create a document cont...
CVE-2024-37829
- EPSS 0.27%
- Veröffentlicht 09.07.2024 21:15:14
- Zuletzt bearbeitet 10.10.2025 16:41:10
An issue in Outline <= v0.76.1 allows attackers to execute a session hijacking attack via user interaction with a crafted magic sign-in link.
CVE-2024-37830
- EPSS 0.16%
- Veröffentlicht 09.07.2024 20:15:11
- Zuletzt bearbeitet 21.11.2024 09:24:21
An issue in Outline <= v0.76.1 allows attackers to redirect a victim user to a malicious site via intercepting and changing the state cookie.
CVE-2023-3532
- EPSS 0.11%
- Veröffentlicht 07.07.2023 03:15:09
- Zuletzt bearbeitet 21.11.2024 08:17:28
Cross-site Scripting (XSS) - Stored in GitHub repository outline/outline prior to 0.70.1.
CVE-2022-2342
- EPSS 0.28%
- Veröffentlicht 07.07.2022 10:15:08
- Zuletzt bearbeitet 21.11.2024 07:00:48
Cross-site Scripting (XSS) - Stored in GitHub repository outline/outline prior to v0.64.4.