Vulnerabilities (CVE)

Filtered by vendor Bookstackapp Subscribe
Filtered by product Bookstack
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-4194 1 Bookstackapp 1 Bookstack 2022-07-25 4.0 MEDIUM 6.5 MEDIUM
bookstack is vulnerable to Improper Access Control
CVE-2021-3944 1 Bookstackapp 1 Bookstack 2021-12-04 4.0 MEDIUM 6.8 MEDIUM
bookstack is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-4026 1 Bookstackapp 1 Bookstack 2021-12-01 4.0 MEDIUM 4.3 MEDIUM
bookstack is vulnerable to Improper Access Control
CVE-2021-3915 1 Bookstackapp 1 Bookstack 2021-11-17 3.5 LOW 5.7 MEDIUM
bookstack is vulnerable to Unrestricted Upload of File with Dangerous Type
CVE-2021-3916 1 Bookstackapp 1 Bookstack 2021-11-09 4.0 MEDIUM 6.5 MEDIUM
bookstack is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2021-3906 1 Bookstackapp 1 Bookstack 2021-11-03 4.0 MEDIUM 6.5 MEDIUM
bookstack is vulnerable to Unrestricted Upload of File with Dangerous Type
CVE-2021-3874 1 Bookstackapp 1 Bookstack 2021-10-20 4.0 MEDIUM 6.5 MEDIUM
bookstack is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2021-3758 1 Bookstackapp 1 Bookstack 2021-09-10 4.0 MEDIUM 6.5 MEDIUM
bookstack is vulnerable to Server-Side Request Forgery (SSRF)
CVE-2021-3767 1 Bookstackapp 1 Bookstack 2021-09-09 3.5 LOW 5.4 MEDIUM
bookstack is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-3768 1 Bookstackapp 1 Bookstack 2021-09-09 3.5 LOW 5.4 MEDIUM
bookstack is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-26260 1 Bookstackapp 1 Bookstack 2020-12-10 5.5 MEDIUM 6.4 MEDIUM
BookStack is a platform for storing and organising information and documentation. In BookStack before version 0.30.5, a user with permissions to edit a page could set certain image URL's to manipulate functionality in the exporting system, which would allow them to make server side requests and/or have access to a wider scope of files within the BookStack file storage locations. The issue was addressed in BookStack v0.30.5. As a workaround, page edit permissions could be limited to only those that are trusted until you can upgrade.
CVE-2020-11055 1 Bookstackapp 1 Bookstack 2020-05-13 3.5 LOW 5.4 MEDIUM
In BookStack greater than or equal to 0.18.0 and less than 0.29.2, there is an XSS vulnerability in comment creation. A user with permission to create comments could POST HTML directly to the system to be saved in a comment, which would then be executed/displayed to others users viewing the comment. Through this vulnerability custom JavaScript code could be injected and therefore ran on other user machines. This most impacts scenarios where not-trusted users are given permission to create comments. This has been fixed in 0.29.2.
CVE-2017-1000462 1 Bookstackapp 1 Bookstack 2018-01-17 3.5 LOW 5.4 MEDIUM
BookStack version 0.18.4 is vulnerable to stored cross-site scripting, within the page creation page, which can result in disruption of service and execution of javascript code.