VYPR
Medium severity5.8NVD Advisory· Published Oct 26, 2020· Updated Jun 17, 2026

CVE-2020-15274

CVE-2020-15274

Description

In Wiki.js before version 2.5.162, an XSS payload can be injected in a page title and executed via the search results. While the title is properly escaped in both the navigation links and the actual page title, it is not the case in the search results. Commit a57d9af34c15adbf460dde6553d964efddf433de fixes this vulnerability (version 2.5.162) by properly escaping the text content displayed in the search results.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Wiki.js/Wiki.jsllm-fuzzy
    Range: <2.5.162
  • Requarks/Wikillm-fuzzy2 versions
    <2.5.162+ 1 more
    • (no CPE)range: <2.5.162
    • (no CPE)range: < 2.5.162

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.