VYPR

Bookstack

by Bookstackapp

Source repositories

CVEs (27)

  • CVE-2017-1000462MedJan 3, 2018
    risk 0.35cvss 5.4epss 0.01

    BookStack version 0.18.4 is vulnerable to stored cross-site scripting, within the page creation page, which can result in disruption of service and execution of javascript code.

  • CVE-2021-3915MedNov 13, 2021
    risk 0.30cvss 5.7epss 0.01

    bookstack is vulnerable to Unrestricted Upload of File with Dangerous Type

  • CVE-2022-0877MedMar 8, 2022
    risk 0.28cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository bookstackapp/bookstack prior to v22.02.3.

  • CVE-2026-5484MedApr 3, 2026
    risk 0.27cvss 5.3epss 0.01

    A weakness has been identified in BookStackApp BookStack up to 26.03. Affected is the function chapterToMarkdown of the file app/Exports/ExportFormatter.php of the component Chapter Export Handler. Executing a manipulation of the argument pages can lead to improper access…

  • CVE-2026-86285MedSep 7, 2026
    risk 0.21cvss 4.3epss 0.00

    A vulnerability was detected in BookStack up to 26.05.2. Affected by this issue is the function AttachmentController::getUpdateForm of the file app/Uploads/Controllers/AttachmentController.php of the component Attachment Edit Endpoint. The manipulation of the argument ID results…

  • CVE-2021-4026MedNov 30, 2021
    risk 0.21cvss 4.3epss 0.01

    bookstack is vulnerable to Improper Access Control

  • CVE-2023-4624LowAug 30, 2023
    risk 0.00cvss 2.4epss 0.01

    Server-Side Request Forgery (SSRF) in GitHub repository bookstackapp/bookstack prior to v23.08.

Page 2 of 2