Bookstack
by Bookstackapp
Source repositories
CVEs (27)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2017-1000462 | Med | 0.35 | 5.4 | 0.01 | Jan 3, 2018 | BookStack version 0.18.4 is vulnerable to stored cross-site scripting, within the page creation page, which can result in disruption of service and execution of javascript code. | ||
| CVE-2021-3915 | Med | 0.30 | 5.7 | 0.01 | Nov 13, 2021 | bookstack is vulnerable to Unrestricted Upload of File with Dangerous Type | ||
| CVE-2022-0877 | Med | 0.28 | 5.4 | 0.01 | Mar 8, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository bookstackapp/bookstack prior to v22.02.3. | ||
| CVE-2026-5484 | Med | 0.27 | 5.3 | 0.01 | Apr 3, 2026 | A weakness has been identified in BookStackApp BookStack up to 26.03. Affected is the function chapterToMarkdown of the file app/Exports/ExportFormatter.php of the component Chapter Export Handler. Executing a manipulation of the argument pages can lead to improper access… | ||
| CVE-2026-86285 | Med | 0.21 | 4.3 | 0.00 | Sep 7, 2026 | A vulnerability was detected in BookStack up to 26.05.2. Affected by this issue is the function AttachmentController::getUpdateForm of the file app/Uploads/Controllers/AttachmentController.php of the component Attachment Edit Endpoint. The manipulation of the argument ID results… | ||
| CVE-2021-4026 | Med | 0.21 | 4.3 | 0.01 | Nov 30, 2021 | bookstack is vulnerable to Improper Access Control | ||
| CVE-2023-4624 | Low | 0.00 | 2.4 | 0.01 | Aug 30, 2023 | Server-Side Request Forgery (SSRF) in GitHub repository bookstackapp/bookstack prior to v23.08. |
- risk 0.35cvss 5.4epss 0.01
BookStack version 0.18.4 is vulnerable to stored cross-site scripting, within the page creation page, which can result in disruption of service and execution of javascript code.
- risk 0.30cvss 5.7epss 0.01
bookstack is vulnerable to Unrestricted Upload of File with Dangerous Type
- risk 0.28cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository bookstackapp/bookstack prior to v22.02.3.
- risk 0.27cvss 5.3epss 0.01
A weakness has been identified in BookStackApp BookStack up to 26.03. Affected is the function chapterToMarkdown of the file app/Exports/ExportFormatter.php of the component Chapter Export Handler. Executing a manipulation of the argument pages can lead to improper access…
- risk 0.21cvss 4.3epss 0.00
A vulnerability was detected in BookStack up to 26.05.2. Affected by this issue is the function AttachmentController::getUpdateForm of the file app/Uploads/Controllers/AttachmentController.php of the component Attachment Edit Endpoint. The manipulation of the argument ID results…
- risk 0.21cvss 4.3epss 0.01
bookstack is vulnerable to Improper Access Control
- risk 0.00cvss 2.4epss 0.01
Server-Side Request Forgery (SSRF) in GitHub repository bookstackapp/bookstack prior to v23.08.
Page 2 of 2