VYPR

Bookstackapp/bookstack

by Bookstackapp

Source repositories

CVEs (21)

  • CVE-2021-4119CriDec 15, 2021
    risk 0.59cvss 9.8epss 0.27

    bookstack is vulnerable to Improper Access Control

  • CVE-2020-5256HigMar 9, 2020
    risk 0.52cvss 7.9epss 0.02

    BookStack before version 0.25.5 has a vulnerability where a user could upload PHP files through image upload functions, which would allow them to execute code on the host system remotely. They would then have the permissions of the PHP process. This most impacts scenarios where…

  • CVE-2020-26211HigNov 3, 2020
    risk 0.43cvss 7.7epss 0.01

    In BookStack before version 0.30.4, a user with permissions to edit a page could insert JavaScript code through the use of `javascript:` URIs within a link or form which would run, within the context of the current page, when clicked or submitted. Additionally, a user with…

  • CVE-2024-36676HigJul 9, 2024
    risk 0.42cvss 7.5epss 0.01

    Incorrect access control in BookStack before v24.05.1 allows attackers to confirm existing system users and perform targeted notification email DoS via public facing forms.

  • CVE-2020-26260MedDec 9, 2020
    risk 0.42cvss 6.4epss 0.01

    BookStack is a platform for storing and organising information and documentation. In BookStack before version 0.30.5, a user with permissions to edit a page could set certain image URL's to manipulate functionality in the exporting system, which would allow them to make server…

  • CVE-2020-11055MedMay 7, 2020
    risk 0.41cvss 6.3epss 0.01

    In BookStack greater than or equal to 0.18.0 and less than 0.29.2, there is an XSS vulnerability in comment creation. A user with permission to create comments could POST HTML directly to the system to be saved in a comment, which would then be executed/displayed to others users…

  • CVE-2021-3944MedDec 2, 2021
    risk 0.37cvss 6.8epss 0.01

    bookstack is vulnerable to Cross-Site Request Forgery (CSRF)

  • CVE-2022-40690MedOct 24, 2022
    risk 0.35cvss 5.4epss 0.01

    Cross-site scripting vulnerability in BookStack versions prior to v22.09 allows a remote authenticated attacker to inject an arbitrary script.

  • CVE-2021-4194MedJan 6, 2022
    risk 0.35cvss 6.5epss 0.01

    bookstack is vulnerable to Improper Access Control

  • CVE-2017-1000462MedJan 3, 2018
    risk 0.35cvss 5.4epss 0.01

    BookStack version 0.18.4 is vulnerable to stored cross-site scripting, within the page creation page, which can result in disruption of service and execution of javascript code.

  • CVE-2021-3915MedNov 13, 2021
    risk 0.30cvss 5.7epss 0.01

    bookstack is vulnerable to Unrestricted Upload of File with Dangerous Type

  • CVE-2022-0877MedMar 8, 2022
    risk 0.28cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository bookstackapp/bookstack prior to v22.02.3.

  • CVE-2021-4026MedNov 30, 2021
    risk 0.21cvss 4.3epss 0.01

    bookstack is vulnerable to Improper Access Control

  • CVE-2023-4624LowAug 30, 2023
    risk 0.00cvss 2.4epss 0.01

    Server-Side Request Forgery (SSRF) in GitHub repository bookstackapp/bookstack prior to v23.08.

  • CVE-2021-3916MedNov 5, 2021
    risk 0.00cvss 6.5epss 0.01

    bookstack is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

  • CVE-2021-3906MedOct 27, 2021
    risk 0.00cvss 6.5epss 0.01

    bookstack is vulnerable to Unrestricted Upload of File with Dangerous Type

  • CVE-2021-3874MedOct 15, 2021
    risk 0.00cvss 6.5epss 0.01

    bookstack is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

  • CVE-2021-3768MedSep 6, 2021
    risk 0.00cvss 5.4epss 0.01

    bookstack is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CVE-2021-3767MedSep 6, 2021
    risk 0.00cvss 5.4epss 0.01

    bookstack is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CVE-2021-3758MedSep 2, 2021
    risk 0.00cvss 6.5epss 0.01

    bookstack is vulnerable to Server-Side Request Forgery (SSRF)

Page 1 of 2