Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2023-6199
Book Stack version 23.10.2 allows filtering local files on the server. This is possible because the application is vulnerable to SSRF.
Bookstack
No fix yet
MEDIUM 5.4
CVE-2022-40690
Cross-site scripting vulnerability in BookStack versions prior to v22.09 allows a remote authenticated attacker to inject an arbitrary script.
Bookstack
22.09+
MEDIUM 5.4
CVE-2022-0877
Cross-site Scripting (XSS) - Stored in GitHub repository bookstackapp/bookstack prior to v22.02.3.
Bookstack
22.02.3+
MEDIUM 6.5
CVE-2021-4194
bookstack is vulnerable to Improper Access Control
Bookstack
21.12.1+
CRITICAL 9.8
CVE-2021-4119EPSS 27%
bookstack is vulnerable to Improper Access Control
Bookstack
after 21.11.2
MEDIUM 6.8
CVE-2021-3944
bookstack is vulnerable to Cross-Site Request Forgery (CSRF)
Bookstack
21.11+
MEDIUM 5.7
CVE-2021-3915
bookstack is vulnerable to Unrestricted Upload of File with Dangerous Type
Bookstack
21.10.3+
MEDIUM 6.5
CVE-2021-3916
bookstack is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Bookstack
21.10.3+
MEDIUM 6.5
CVE-2021-3906
bookstack is vulnerable to Unrestricted Upload of File with Dangerous Type
Bookstack
21.10.1+
MEDIUM 6.5
CVE-2021-3874
bookstack is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Bookstack
21.08.5+
MEDIUM 5.4
CVE-2021-3767
bookstack is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Bookstack
21.08.2+
MEDIUM 5.4
CVE-2021-3768
bookstack is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Bookstack
21.08.2+
MEDIUM 6.5
CVE-2021-3758
bookstack is vulnerable to Server-Side Request Forgery (SSRF)
Bookstack
21.08+
MEDIUM 6.4
CVE-2020-26260
BookStack is a platform for storing and organising information and documentation. In BookStack before version 0.30.5, a user with permissions to edit…
Bookstack
0.30.5+
HIGH 8.7
CVE-2020-26211
In BookStack before version 0.30.4, a user with permissions to edit a page could insert JavaScript code through the use of `javascript:` URIs within …
Bookstack
0.30.4+
HIGH 8.7
CVE-2020-26210
In BookStack before version 0.30.4, a user with permissions to edit a page could add an attached link which would execute untrusted JavaScript code w…
Bookstack
0.30.4+
MEDIUM 5.4
CVE-2020-11055
In BookStack greater than or equal to 0.18.0 and less than 0.29.2, there is an XSS vulnerability in comment creation. A user with permission to creat…
Bookstack
0.29.2+
HIGH 8.8
CVE-2020-5256
BookStack before version 0.25.5 has a vulnerability where a user could upload PHP files through image upload functions, which would allow them to exe…
Bookstack
0.25.3+
MEDIUM 5.4
CVE-2017-1000462
BookStack version 0.18.4 is vulnerable to stored cross-site scripting, within the page creation page, which can result in disruption of service and e…
Bookstack
No fix yet