CVE-2026-48073
- EPSS 0.19%
- Veröffentlicht 24.09.2026 18:33:20
- Zuletzt bearbeitet 24.09.2026 20:17:29
Docmost is open-source collaborative wiki and documentation software. From 0.70.0 until 0.80.1, a low-privileged authenticated user who can edit an exportable page can embed a forged attachmentId that belongs to a restricted page in the same space. E...
CVE-2026-52853
- EPSS 0.21%
- Veröffentlicht 24.09.2026 18:31:54
- Zuletzt bearbeitet 05.10.2026 16:17:14
Docmost is open-source collaborative wiki and documentation software. Prior to 0.90.1, an authenticated workspace ADMIN can use the workspace invitation flow to invite an external email address with the OWNER role because the role ceiling does not pr...
CVE-2026-48072
- EPSS 0.33%
- Veröffentlicht 24.09.2026 18:30:57
- Zuletzt bearbeitet 24.09.2026 19:17:13
Docmost is open-source collaborative wiki and documentation software. Prior to 0.80.1, the public avatar and logo image endpoint accepts attacker-controlled fileName path segments and resolves them against local storage without confinement to the int...
CVE-2026-52850
- EPSS 0.19%
- Veröffentlicht 24.09.2026 18:30:06
- Zuletzt bearbeitet 29.09.2026 04:17:56
Docmost is open-source collaborative wiki and documentation software. Prior to 0.90.1, an authenticated workspace member who does not belong to a private space can call the transclusion / sync-block lookup API with a known sourcePageId and transclusi...
CVE-2026-65827
- EPSS 0.3%
- Veröffentlicht 24.09.2026 18:28:36
- Zuletzt bearbeitet 24.09.2026 20:17:29
Docmost is open-source collaborative wiki and documentation software. From 0.21.0 until 0.95.0, any authenticated workspace member with edit rights to a space can upload an archive to the page-import feature whose ZIP extraction routine does not limi...
CVE-2026-48070
- EPSS 0.37%
- Veröffentlicht 24.09.2026 18:15:58
- Zuletzt bearbeitet 05.10.2026 16:17:13
Docmost is open-source collaborative wiki and documentation software. Prior to 0.80.1, authenticated users can store attacker-controlled avatarUrl values that are later reused by avatar cleanup without confinement to the intended directory on local-s...
CVE-2025-57231
- EPSS 0.39%
- Veröffentlicht 10.09.2026 00:00:00
- Zuletzt bearbeitet 22.09.2026 20:00:03
Path Traversal in avatar attachments in Docmost v0.21.0 allows an unauthenticated malicious actor to disclose local files via a POST Request in a public url.
CVE-2026-40927
- EPSS 0.14%
- Veröffentlicht 21.04.2026 20:52:29
- Zuletzt bearbeitet 23.04.2026 15:50:16
Docmost is open-source collaborative wiki and documentation software. Prior to 0.80.0, when leaving a comment on a page, it is possible to include a JavaScript URI as the link. When a user clicks on the link the JavaScript executes. This vulnerabilit...
CVE-2026-34213
- EPSS 0.22%
- Veröffentlicht 14.04.2026 21:49:55
- Zuletzt bearbeitet 24.07.2026 22:10:00
Docmost is open-source collaborative wiki and documentation software. Starting in version 0.3.0 and prior to version 0.71.0, improper authorization in Docmost allows a low-privileged authenticated user to overwrite another page's attachment within th...
CVE-2026-34212
- EPSS 0.21%
- Veröffentlicht 14.04.2026 21:42:44
- Zuletzt bearbeitet 24.07.2026 22:10:00
Docmost is open-source collaborative wiki and documentation software. In versions prior to 0.71.0, improper neutralization of attachment URLs in Docmost allows a low-privileged authenticated user to store a malicious `javascript:` URL inside an attac...