Medium severity5.4NVD Advisory· Published Apr 14, 2026· Updated Apr 22, 2026
CVE-2026-34212
CVE-2026-34212
Description
Docmost is open-source collaborative wiki and documentation software. In versions prior to 0.71.0, improper neutralization of attachment URLs in Docmost allows a low-privileged authenticated user to store a malicious javascript: URL inside an attachment node in page content. When another user views the page and activates the attachment link/icon, attacker-controlled JavaScript executes in the context of the Docmost origin. Version 0.71.0 patches the issue.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- github.com/docmost/docmost/security/advisories/GHSA-cf68-cff9-hq4wnvdExploitVendor Advisory
News mentions
0No linked articles in our index yet.