Bookstack
by Bookstackapp
Source repositories
CVEs (27)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-4119 | Cri | 0.59 | 9.8 | 0.27 | Dec 15, 2021 | bookstack is vulnerable to Improper Access Control | ||
| CVE-2020-5256 | Hig | 0.52 | 7.9 | 0.02 | Mar 9, 2020 | BookStack before version 0.25.5 has a vulnerability where a user could upload PHP files through image upload functions, which would allow them to execute code on the host system remotely. They would then have the permissions of the PHP process. This most impacts scenarios where… | ||
| CVE-2026-84695 | Hig | 0.50 | 8.7 | 0.00 | Sep 2, 2026 | BookStack before 26.05.4 contains a stored cross-site scripting vulnerability in the drawing upload endpoint that accepts unvalidated base64 content and stores it without content inspection. Attackers with editor permissions can upload SVG files containing scripts that execute… | ||
| CVE-2026-82450 | Hig | 0.50 | 8.8 | 0.01 | Aug 29, 2026 | BookStack before 26.05.4 contains a remote code execution vulnerability in the portable ZIP import functionality that allows users with Import Content and Create Books permissions to upload a PHP polyglot file as a book cover. Attackers can bypass image extension validation by… | ||
| CVE-2020-26210 | Hig | 0.50 | 7.7 | 0.01 | Nov 3, 2020 | In BookStack before version 0.30.4, a user with permissions to edit a page could add an attached link which would execute untrusted JavaScript code when clicked by a viewer of the page. Dangerous content may remain in the database after this update. If you think this could have… | ||
| CVE-2026-89022 | Hig | 0.48 | 7.4 | 0.00 | Sep 15, 2026 | BookStack before 26.05.5 contains an authentication bypass vulnerability in its social login implementation that allows unauthenticated attackers to sign in as arbitrary users by authenticating through a different social provider sharing the same driver_id namespace. Attackers… | ||
| CVE-2020-26211 | Hig | 0.43 | 7.7 | 0.01 | Nov 3, 2020 | In BookStack before version 0.30.4, a user with permissions to edit a page could insert JavaScript code through the use of `javascript:` URIs within a link or form which would run, within the context of the current page, when clicked or submitted. Additionally, a user with… | ||
| CVE-2023-6199 | Med | 0.42 | 6.5 | 0.01 | Nov 20, 2023 | Book Stack version 23.10.2 allows filtering local files on the server. This is possible because the application is vulnerable to SSRF. | ||
| CVE-2021-3916 | Med | 0.42 | 6.5 | 0.01 | Nov 5, 2021 | bookstack is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | ||
| CVE-2021-3906 | Med | 0.42 | 6.5 | 0.01 | Oct 27, 2021 | bookstack is vulnerable to Unrestricted Upload of File with Dangerous Type | ||
| CVE-2021-3874 | Med | 0.42 | 6.5 | 0.01 | Oct 15, 2021 | bookstack is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | ||
| CVE-2021-3758 | Med | 0.42 | 6.5 | 0.01 | Sep 2, 2021 | bookstack is vulnerable to Server-Side Request Forgery (SSRF) | ||
| CVE-2020-26260 | Med | 0.42 | 6.4 | 0.01 | Dec 9, 2020 | BookStack is a platform for storing and organising information and documentation. In BookStack before version 0.30.5, a user with permissions to edit a page could set certain image URL's to manipulate functionality in the exporting system, which would allow them to make server… | ||
| CVE-2020-11055 | Med | 0.41 | 6.3 | 0.01 | May 7, 2020 | In BookStack greater than or equal to 0.18.0 and less than 0.29.2, there is an XSS vulnerability in comment creation. A user with permission to create comments could POST HTML directly to the system to be saved in a comment, which would then be executed/displayed to others users… | ||
| CVE-2021-3944 | Med | 0.37 | 6.8 | 0.01 | Dec 2, 2021 | bookstack is vulnerable to Cross-Site Request Forgery (CSRF) | ||
| CVE-2026-67204 | Med | 0.35 | 5.4 | 0.00 | Aug 24, 2026 | BookStack before 26.05.4 contains a broken access control vulnerability that allows authenticated API users with image-update or image-delete permissions to manipulate other users' avatars by exploiting missing content-type restrictions in the Image Gallery API endpoints.… | ||
| CVE-2022-40690 | Med | 0.35 | 5.4 | 0.01 | Oct 24, 2022 | Cross-site scripting vulnerability in BookStack versions prior to v22.09 allows a remote authenticated attacker to inject an arbitrary script. | ||
| CVE-2021-4194 | Med | 0.35 | 6.5 | 0.01 | Jan 6, 2022 | bookstack is vulnerable to Improper Access Control | ||
| CVE-2021-3768 | Med | 0.35 | 5.4 | 0.01 | Sep 6, 2021 | bookstack is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | ||
| CVE-2021-3767 | Med | 0.35 | 5.4 | 0.01 | Sep 6, 2021 | bookstack is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
- risk 0.59cvss 9.8epss 0.27
bookstack is vulnerable to Improper Access Control
- risk 0.52cvss 7.9epss 0.02
BookStack before version 0.25.5 has a vulnerability where a user could upload PHP files through image upload functions, which would allow them to execute code on the host system remotely. They would then have the permissions of the PHP process. This most impacts scenarios where…
- risk 0.50cvss 8.7epss 0.00
BookStack before 26.05.4 contains a stored cross-site scripting vulnerability in the drawing upload endpoint that accepts unvalidated base64 content and stores it without content inspection. Attackers with editor permissions can upload SVG files containing scripts that execute…
- risk 0.50cvss 8.8epss 0.01
BookStack before 26.05.4 contains a remote code execution vulnerability in the portable ZIP import functionality that allows users with Import Content and Create Books permissions to upload a PHP polyglot file as a book cover. Attackers can bypass image extension validation by…
- risk 0.50cvss 7.7epss 0.01
In BookStack before version 0.30.4, a user with permissions to edit a page could add an attached link which would execute untrusted JavaScript code when clicked by a viewer of the page. Dangerous content may remain in the database after this update. If you think this could have…
- risk 0.48cvss 7.4epss 0.00
BookStack before 26.05.5 contains an authentication bypass vulnerability in its social login implementation that allows unauthenticated attackers to sign in as arbitrary users by authenticating through a different social provider sharing the same driver_id namespace. Attackers…
- risk 0.43cvss 7.7epss 0.01
In BookStack before version 0.30.4, a user with permissions to edit a page could insert JavaScript code through the use of `javascript:` URIs within a link or form which would run, within the context of the current page, when clicked or submitted. Additionally, a user with…
- risk 0.42cvss 6.5epss 0.01
Book Stack version 23.10.2 allows filtering local files on the server. This is possible because the application is vulnerable to SSRF.
- risk 0.42cvss 6.5epss 0.01
bookstack is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
- risk 0.42cvss 6.5epss 0.01
bookstack is vulnerable to Unrestricted Upload of File with Dangerous Type
- risk 0.42cvss 6.5epss 0.01
bookstack is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
- risk 0.42cvss 6.5epss 0.01
bookstack is vulnerable to Server-Side Request Forgery (SSRF)
- risk 0.42cvss 6.4epss 0.01
BookStack is a platform for storing and organising information and documentation. In BookStack before version 0.30.5, a user with permissions to edit a page could set certain image URL's to manipulate functionality in the exporting system, which would allow them to make server…
- risk 0.41cvss 6.3epss 0.01
In BookStack greater than or equal to 0.18.0 and less than 0.29.2, there is an XSS vulnerability in comment creation. A user with permission to create comments could POST HTML directly to the system to be saved in a comment, which would then be executed/displayed to others users…
- risk 0.37cvss 6.8epss 0.01
bookstack is vulnerable to Cross-Site Request Forgery (CSRF)
- risk 0.35cvss 5.4epss 0.00
BookStack before 26.05.4 contains a broken access control vulnerability that allows authenticated API users with image-update or image-delete permissions to manipulate other users' avatars by exploiting missing content-type restrictions in the Image Gallery API endpoints.…
- risk 0.35cvss 5.4epss 0.01
Cross-site scripting vulnerability in BookStack versions prior to v22.09 allows a remote authenticated attacker to inject an arbitrary script.
- risk 0.35cvss 6.5epss 0.01
bookstack is vulnerable to Improper Access Control
- risk 0.35cvss 5.4epss 0.01
bookstack is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- risk 0.35cvss 5.4epss 0.01
bookstack is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Page 1 of 2