VYPR

leafwiki

by Perber

Source repositories

CVEs (4)

  • CVE-2026-53528HigAug 21, 2026
    risk 0.57cvss 8.8epss 0.01

    LeafWiki is a self-hosted wiki. Versions 0.3.0 through 0.10.0 have a path traversal vulnerability in LeafWiki’s asset rename functionality. An authenticated user with editor permissions could move files that are accessible to the LeafWiki server process into a page’s asset…

  • CVE-2026-53527HigAug 21, 2026
    risk 0.57cvss 8.8epss 0.00

    LeafWiki is a self-hosted wiki. Versions 0.1.0 through 0.10.0 have a privilege escalation vulnerability in the user update API. An authenticated user could update their own account role and escalate privileges from a regular user, such as `viewer`, to `admin`. Exploitation…

  • CVE-2026-80189MedAug 26, 2026
    risk 0.35cvss 6.5epss 0.01

    LeafWiki extracts an uploaded ZIP archive without limiting how much data it will write. ZipExtractor.ExtractToDir in internal/importer/zip_extractor.go opens each entry and copies it to the destination with io.Copy, which runs to the end of the decompressed stream, so only the…

  • CVE-2026-53529MedAug 21, 2026
    risk 0.31cvss —epss 0.00

    LeafWiki is a self-hosted wiki. Prior to version 0.10.2, page titles returned by the search API could be rendered as raw HTML in the frontend. A user with editor or administrator permissions could create or modify a page title containing an HTML/JavaScript payload. When another…