Vulnerability index

Browse CVEs

19 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Bookstack MEDIUM 6.5
CVE-2023-6199

Book Stack version 23.10.2 allows filtering local files on the server. This is possible because the application is vulnerable to SSRF.

No fix yet
Fix from $1,600 2023-11-20
Bookstack MEDIUM 5.4
CVE-2022-40690

Cross-site scripting vulnerability in BookStack versions prior to v22.09 allows a remote authenticated attacker to inject an arbitrary script.

Fix: 22.09+
Fix from $1,600 2022-10-24
Bookstack MEDIUM 5.4
CVE-2022-0877

Cross-site Scripting (XSS) - Stored in GitHub repository bookstackapp/bookstack prior to v22.02.3.

Fix: 22.02.3+
Fix from $1,600 2022-03-08
Bookstack MEDIUM 6.5
CVE-2021-4194

bookstack is vulnerable to Improper Access Control

Fix: 21.12.1+
Fix from $1,600 2022-01-06
Bookstack CRITICAL 9.8
CVE-2021-4119EPSS 27%

bookstack is vulnerable to Improper Access Control

Fix: after 21.11.2
Fix from $2,300 2021-12-15
Bookstack MEDIUM 6.8
CVE-2021-3944

bookstack is vulnerable to Cross-Site Request Forgery (CSRF)

Fix: 21.11+
Fix from $1,600 2021-12-02
Bookstack MEDIUM 5.7
CVE-2021-3915

bookstack is vulnerable to Unrestricted Upload of File with Dangerous Type

Fix: 21.10.3+
Fix from $1,600 2021-11-13
Bookstack MEDIUM 6.5
CVE-2021-3916

bookstack is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Fix: 21.10.3+
Fix from $1,600 2021-11-05
Bookstack MEDIUM 6.5
CVE-2021-3906

bookstack is vulnerable to Unrestricted Upload of File with Dangerous Type

Fix: 21.10.1+
Fix from $1,600 2021-10-27
Bookstack MEDIUM 6.5
CVE-2021-3874

bookstack is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Fix: 21.08.5+
Fix from $1,600 2021-10-15
Bookstack MEDIUM 5.4
CVE-2021-3767

bookstack is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Fix: 21.08.2+
Fix from $1,600 2021-09-06
Bookstack MEDIUM 5.4
CVE-2021-3768

bookstack is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Fix: 21.08.2+
Fix from $1,600 2021-09-06
Bookstack MEDIUM 6.5
CVE-2021-3758

bookstack is vulnerable to Server-Side Request Forgery (SSRF)

Fix: 21.08+
Fix from $1,600 2021-09-02
Bookstack MEDIUM 6.4
CVE-2020-26260

BookStack is a platform for storing and organising information and documentation. In BookStack before version 0.30.5, a user with permissions to edit…

Fix: 0.30.5+
Fix from $1,600 2020-12-09
Bookstack HIGH 8.7
CVE-2020-26211

In BookStack before version 0.30.4, a user with permissions to edit a page could insert JavaScript code through the use of `javascript:` URIs within …

Fix: 0.30.4+
Fix from $1,950 2020-11-03
Bookstack HIGH 8.7
CVE-2020-26210

In BookStack before version 0.30.4, a user with permissions to edit a page could add an attached link which would execute untrusted JavaScript code w…

Fix: 0.30.4+
Fix from $1,950 2020-11-03
Bookstack MEDIUM 5.4
CVE-2020-11055

In BookStack greater than or equal to 0.18.0 and less than 0.29.2, there is an XSS vulnerability in comment creation. A user with permission to creat…

Fix: 0.29.2+
Fix from $1,600 2020-05-07
Bookstack HIGH 8.8
CVE-2020-5256

BookStack before version 0.25.5 has a vulnerability where a user could upload PHP files through image upload functions, which would allow them to exe…

Fix: 0.25.3+
Fix from $1,950 2020-03-09
Bookstack MEDIUM 5.4
CVE-2017-1000462

BookStack version 0.18.4 is vulnerable to stored cross-site scripting, within the page creation page, which can result in disruption of service and e…

No fix yet
Fix from $1,600 2018-01-03