Bookstackapp
Bookstackapp Bookstack: vulnerabilidades y CVE
Bookstackapp Bookstack tiene 28 vulnerabilidades publicadas, 6 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE28
Últimos 12 meses6
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-89022 | Crítica (9.1) | 0.46% | — | 15 sept 2026 | BookStack before 26.05.5 contains an authentication bypass vulnerability in its social login implementation that allows unauthenticated attackers to sign in as arbitrary users by authenticating through a different… |
| CVE-2026-86285 | Baja (2.1) | 0.39% | — | 7 sept 2026 | A vulnerability was detected in BookStack up to 26.05.2. Affected by this issue is the function AttachmentController::getUpdateForm of the file app/Uploads/Controllers/AttachmentController.php of the component… |
| CVE-2026-84695 | Crítica (9.3) | 0.47% | — | 2 sept 2026 | BookStack before 26.05.4 contains a stored cross-site scripting vulnerability in the drawing upload endpoint that accepts unvalidated base64 content and stores it without content inspection. Attackers with editor… |
| CVE-2026-82450 | Alta (8.7) | 1.00% | — | 29 ago 2026 | BookStack before 26.05.4 contains a remote code execution vulnerability in the portable ZIP import functionality that allows users with Import Content and Create Books permissions to upload a PHP polyglot file as a book… |
| CVE-2026-67204 | Media (5.3) | 0.41% | — | 24 ago 2026 | BookStack before 26.05.4 contains a broken access control vulnerability that allows authenticated API users with image-update or image-delete permissions to manipulate other users' avatars by exploiting missing… |
| CVE-2026-5484 | Media (5.5) | 0.55% | — | 3 abr 2026 | A weakness has been identified in BookStackApp BookStack up to 26.03. Affected is the function chapterToMarkdown of the file app/Exports/ExportFormatter.php of the component Chapter Export Handler. Executing a… |
| CVE-2024-36676 | Alta (7.5) | 0.65% | — | 9 jul 2024 | Incorrect access control in BookStack before v24.05.1 allows attackers to confirm existing system users and perform targeted notification email DoS via public facing forms. |
| CVE-2023-6199 | Media (6.5) | 1.4% | — | 20 nov 2023 | Book Stack version 23.10.2 allows filtering local files on the server. This is possible because the application is vulnerable to SSRF. |
| CVE-2023-4624 | Baja (2.4) | 0.63% | — | 30 ago 2023 | Server-Side Request Forgery (SSRF) in GitHub repository bookstackapp/bookstack prior to v23.08. |
| CVE-2022-40690 | Media (5.4) | 0.77% | — | 24 oct 2022 | Cross-site scripting vulnerability in BookStack versions prior to v22.09 allows a remote authenticated attacker to inject an arbitrary script. |
| CVE-2022-0877 | Media (5.4) | 0.78% | — | 8 mar 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository bookstackapp/bookstack prior to v22.02.3. |
| CVE-2021-4194 | Media (6.5) | 0.71% | — | 6 ene 2022 | bookstack is vulnerable to Improper Access Control |
| CVE-2021-4119 | Crítica (9.8) | 27% | — | 15 dic 2021 | bookstack is vulnerable to Improper Access Control |
| CVE-2021-3944 | Media (6.8) | 0.64% | — | 2 dic 2021 | bookstack is vulnerable to Cross-Site Request Forgery (CSRF) |
| CVE-2021-4026 | Media (4.3) | 0.93% | — | 30 nov 2021 | bookstack is vulnerable to Improper Access Control |
| CVE-2021-3915 | Media (5.7) | 0.96% | — | 13 nov 2021 | bookstack is vulnerable to Unrestricted Upload of File with Dangerous Type |
| CVE-2021-3916 | Media (6.5) | 1.2% | — | 5 nov 2021 | bookstack is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
| CVE-2021-3906 | Media (6.5) | 0.67% | — | 27 oct 2021 | bookstack is vulnerable to Unrestricted Upload of File with Dangerous Type |
| CVE-2021-3874 | Media (6.5) | 1.2% | — | 15 oct 2021 | bookstack is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
| CVE-2021-3768 | Media (5.4) | 0.58% | — | 6 sept 2021 | bookstack is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2021-3767 | Media (5.4) | 0.58% | — | 6 sept 2021 | bookstack is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2021-3758 | Media (6.5) | 0.80% | — | 2 sept 2021 | bookstack is vulnerable to Server-Side Request Forgery (SSRF) |
| CVE-2020-26260 | Media (6.4) | 0.84% | — | 9 dic 2020 | BookStack is a platform for storing and organising information and documentation. In BookStack before version 0.30.5, a user with permissions to edit a page could set certain image URL's to manipulate functionality in… |
| CVE-2020-26211 | Alta (8.7) | 1.1% | — | 3 nov 2020 | In BookStack before version 0.30.4, a user with permissions to edit a page could insert JavaScript code through the use of `javascript:` URIs within a link or form which would run, within the context of the current… |
| CVE-2020-26210 | Alta (8.7) | 1.2% | — | 3 nov 2020 | In BookStack before version 0.30.4, a user with permissions to edit a page could add an attached link which would execute untrusted JavaScript code when clicked by a viewer of the page. Dangerous content may remain in… |
| CVE-2020-11055 | Media (5.4) | 0.78% | — | 7 may 2020 | In BookStack greater than or equal to 0.18.0 and less than 0.29.2, there is an XSS vulnerability in comment creation. A user with permission to create comments could POST HTML directly to the system to be saved in a… |
| CVE-2020-5256 | Alta (8.8) | 2.0% | — | 9 mar 2020 | BookStack before version 0.25.5 has a vulnerability where a user could upload PHP files through image upload functions, which would allow them to execute code on the host system remotely. They would then have the… |
| CVE-2017-1000462 | Media (5.4) | 0.76% | — | 3 ene 2018 | BookStack version 0.18.4 is vulnerable to stored cross-site scripting, within the page creation page, which can result in disruption of service and execution of javascript code. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.