« Volver al listado

Bookstackapp

Bookstackapp Bookstack: vulnerabilidades y CVE

Bookstackapp Bookstack tiene 28 vulnerabilidades publicadas, 6 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE28
Últimos 12 meses6
Críticas3
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-89022Crítica (9.1)0.46%—15 sept 2026
BookStack before 26.05.5 contains an authentication bypass vulnerability in its social login implementation that allows unauthenticated attackers to sign in as arbitrary users by authenticating through a different…
CVE-2026-86285Baja (2.1)0.39%—7 sept 2026
A vulnerability was detected in BookStack up to 26.05.2. Affected by this issue is the function AttachmentController::getUpdateForm of the file app/Uploads/Controllers/AttachmentController.php of the component…
CVE-2026-84695Crítica (9.3)0.47%—2 sept 2026
BookStack before 26.05.4 contains a stored cross-site scripting vulnerability in the drawing upload endpoint that accepts unvalidated base64 content and stores it without content inspection. Attackers with editor…
CVE-2026-82450Alta (8.7)1.00%—29 ago 2026
BookStack before 26.05.4 contains a remote code execution vulnerability in the portable ZIP import functionality that allows users with Import Content and Create Books permissions to upload a PHP polyglot file as a book…
CVE-2026-67204Media (5.3)0.41%—24 ago 2026
BookStack before 26.05.4 contains a broken access control vulnerability that allows authenticated API users with image-update or image-delete permissions to manipulate other users' avatars by exploiting missing…
CVE-2026-5484Media (5.5)0.55%—3 abr 2026
A weakness has been identified in BookStackApp BookStack up to 26.03. Affected is the function chapterToMarkdown of the file app/Exports/ExportFormatter.php of the component Chapter Export Handler. Executing a…
CVE-2024-36676Alta (7.5)0.65%—9 jul 2024
Incorrect access control in BookStack before v24.05.1 allows attackers to confirm existing system users and perform targeted notification email DoS via public facing forms.
CVE-2023-6199Media (6.5)1.4%—20 nov 2023
Book Stack version 23.10.2 allows filtering local files on the server. This is possible because the application is vulnerable to SSRF.
CVE-2023-4624Baja (2.4)0.63%—30 ago 2023
Server-Side Request Forgery (SSRF) in GitHub repository bookstackapp/bookstack prior to v23.08.
CVE-2022-40690Media (5.4)0.77%—24 oct 2022
Cross-site scripting vulnerability in BookStack versions prior to v22.09 allows a remote authenticated attacker to inject an arbitrary script.
CVE-2022-0877Media (5.4)0.78%—8 mar 2022
Cross-site Scripting (XSS) - Stored in GitHub repository bookstackapp/bookstack prior to v22.02.3.
CVE-2021-4194Media (6.5)0.71%—6 ene 2022
bookstack is vulnerable to Improper Access Control
CVE-2021-4119Crítica (9.8)27%—15 dic 2021
bookstack is vulnerable to Improper Access Control
CVE-2021-3944Media (6.8)0.64%—2 dic 2021
bookstack is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-4026Media (4.3)0.93%—30 nov 2021
bookstack is vulnerable to Improper Access Control
CVE-2021-3915Media (5.7)0.96%—13 nov 2021
bookstack is vulnerable to Unrestricted Upload of File with Dangerous Type
CVE-2021-3916Media (6.5)1.2%—5 nov 2021
bookstack is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2021-3906Media (6.5)0.67%—27 oct 2021
bookstack is vulnerable to Unrestricted Upload of File with Dangerous Type
CVE-2021-3874Media (6.5)1.2%—15 oct 2021
bookstack is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2021-3768Media (5.4)0.58%—6 sept 2021
bookstack is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-3767Media (5.4)0.58%—6 sept 2021
bookstack is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-3758Media (6.5)0.80%—2 sept 2021
bookstack is vulnerable to Server-Side Request Forgery (SSRF)
CVE-2020-26260Media (6.4)0.84%—9 dic 2020
BookStack is a platform for storing and organising information and documentation. In BookStack before version 0.30.5, a user with permissions to edit a page could set certain image URL's to manipulate functionality in…
CVE-2020-26211Alta (8.7)1.1%—3 nov 2020
In BookStack before version 0.30.4, a user with permissions to edit a page could insert JavaScript code through the use of `javascript:` URIs within a link or form which would run, within the context of the current…
CVE-2020-26210Alta (8.7)1.2%—3 nov 2020
In BookStack before version 0.30.4, a user with permissions to edit a page could add an attached link which would execute untrusted JavaScript code when clicked by a viewer of the page. Dangerous content may remain in…
CVE-2020-11055Media (5.4)0.78%—7 may 2020
In BookStack greater than or equal to 0.18.0 and less than 0.29.2, there is an XSS vulnerability in comment creation. A user with permission to create comments could POST HTML directly to the system to be saved in a…
CVE-2020-5256Alta (8.8)2.0%—9 mar 2020
BookStack before version 0.25.5 has a vulnerability where a user could upload PHP files through image upload functions, which would allow them to execute code on the host system remotely. They would then have the…
CVE-2017-1000462Media (5.4)0.76%—3 ene 2018
BookStack version 0.18.4 is vulnerable to stored cross-site scripting, within the page creation page, which can result in disruption of service and execution of javascript code.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1059 Command and Scripting Interpreter1
  2. T1059.007 JavaScript1
  3. T1078 Valid Accounts1
  4. T1189 Drive-by Compromise1
  5. T1190 Exploit Public-Facing Application1
  6. T1210 Exploitation of Remote Services1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.