Vulnerability index

Browse CVEs

13 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Wiki.js HIGH 8.8
CVE-2026-44224

Wiki.js is an open source wiki app built on Node.js. Prior to 2.5.313, the users.update GraphQL mutation accepts an arbitrary groups array and applie…

Fix: 2.5.313+
Fix from $1,950 2026-05-12
Wiki.js CRITICAL 9.1
CVE-2025-56643

Requarks Wiki.js 2.5.307 does not properly revoke or invalidate active JWT tokens when a user logs out. As a result, previously issued tokens remain …

Mitigation only
Fix from $2,300 2025-11-18
Wiki.js HIGH 7.2
CVE-2022-1681

Authentication Bypass Using an Alternate Path or Channel in GitHub repository requarks/wiki prior to 2.5.281. User can get root user permissions

Fix: 2.5.281+
Fix from $1,950 2022-05-12
Wiki.js MEDIUM 6.5
CVE-2022-23654

Wiki.js is a wiki app built on Node.js. In affected versions an authenticated user with write access on a restricted set of paths can update a page o…

Fix: 2.5.276+
Fix from $1,600 2022-02-22
Wiki.js MEDIUM 5.4
CVE-2021-25993

In Requarks wiki.js, versions 2.0.0-beta.147 to 2.5.255 are affected by Stored XSS vulnerability, where a low privileged (editor) user can upload a S…

Fix: after 2.5.255
Fix from $1,600 2021-12-29
Wiki.js MEDIUM 5.4
CVE-2021-43855

Wiki.js is a wiki app built on node.js. Wiki.js 2.5.263 and earlier is vulnerable to stored cross-site scripting through a SVG file upload made via a…

Fix: 2.5.264+
Fix from $1,600 2021-12-27
Wiki.js MEDIUM 5.4
CVE-2021-43856

Wiki.js is a wiki app built on Node.js. Wiki.js 2.5.263 and earlier is vulnerable to stored cross-site scripting through non-image file uploads for f…

Fix: 2.5.264+
Fix from $1,600 2021-12-27
Wiki.js MEDIUM 5.4
CVE-2021-43842

Wiki.js is a wiki app built on Node.js. Wiki.js versions 2.5.257 and earlier are vulnerable to stored cross-site scripting through a SVG file upload.…

Fix: after 2.5.257
Fix from $1,600 2021-12-20
Wiki.js HIGH 7.5
CVE-2021-43800

Wiki.js is a wiki app built on Node.js. Prior to version 2.5.254, directory traversal outside of Wiki.js context is possible when a storage module wi…

Fix: 2.5.245+
Fix from $1,950 2021-12-06
Wiki.js MEDIUM 5.4
CVE-2021-21383

Wiki.js an open-source wiki app built on Node.js. Wiki.js before version 2.5.191 is vulnerable to stored cross-site scripting through mustache expres…

Fix: 2.5.191+
Fix from $1,600 2021-03-18
Wiki.js MEDIUM 5.4
CVE-2020-15274

In Wiki.js before version 2.5.162, an XSS payload can be injected in a page title and executed via the search results. While the title is properly es…

Fix: 2.5.162+
Fix from $1,600 2020-10-26
Wiki.js HIGH 7.5
CVE-2020-15236

In Wiki.js before version 2.5.151, directory traversal outside of Wiki.js context is possible when a storage module with local asset cache fetching i…

Fix: 2.5.151+
Fix from $1,950 2020-10-05
Wiki.js MEDIUM 6.1
CVE-2020-4052

In Wiki.js before 2.4.107, there is a stored cross-site scripting through template injection. This vulnerability exists due to an insecure validation…

Fix: 2.4.107+
Fix from $1,600 2020-06-16