Getoutline
Getoutline Outline: vulnerabilidades y CVE
Getoutline Outline tiene 21 vulnerabilidades publicadas, 15 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE21
Últimos 12 meses15
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-54573 | Media (5.3) | 0.50% | — | 25 jun 2026 | Outline is a service that allows for collaborative documentation. Prior to 1.8.0, the AuthenticationHelper.canAccess function uses ctx.originalUrl to verify if an API key or OAuth token has the required scopes for a… |
| CVE-2026-44695 | Media (6.5) | 0.15% | — | 11 may 2026 | Outline is a service that allows for collaborative documentation. Prior to 1.7.1, the Slack integration callback for GET /auth/slack.post accepts an unsigned, session-independent OAuth state value. A third party who can… |
| CVE-2026-43890 | Alta (7.7) | 0.34% | — | 11 may 2026 | Outline is a service that allows for collaborative documentation. From 0.84.0 to 1.7.0, the subscriptions.create API endpoint in server/routes/api/subscriptions/subscriptions.ts exhibits a broken authorization pattern.… |
| CVE-2026-43889 | Media (6.5) | 0.35% | — | 11 may 2026 | Outline is a service that allows for collaborative documentation. Prior to 1.7.0, the shares.create API accepts both collectionId and documentId simultaneously and, when published=false, only verifies read access for… |
| CVE-2026-43888 | Alta (8.7) | 0.52% | — | 11 may 2026 | Outline is a service that allows for collaborative documentation. Prior to 1.7.0, ZipHelper.extract computes the extraction path for each entry by passing a full filesystem path through trimFileAndExt, a filename helper… |
| CVE-2026-43887 | Alta (7.3) | 0.43% | — | 11 may 2026 | Outline is a service that allows for collaborative documentation. From 0.84.0 to 1.6.1, the Outline comment section permits users to mention other users; however, the backend does not validate or sanitize the href… |
| CVE-2026-43886 | Alta (8.2) | 0.30% | — | 11 may 2026 | Outline is a service that allows for collaborative documentation. From 0.84.0 to 1.6.1, a logic error in OAuthInterface.validateScope() uses Array.some() to validate requested OAuth scopes, causing the function to… |
| CVE-2026-41649 | Alta (7.7) | 0.41% | — | 28 abr 2026 | Outline is a service that allows for collaborative documentation. The `shares.create` API endpoint starting in version 0.86.0 and prior to version 1.7.0 has an insecure direct object reference.. When both `collectionId`… |
| CVE-2026-33640 | Crítica (9.1) | 0.55% | — | 26 mar 2026 | Outline is a service that allows for collaborative documentation. Outline implements an Email OTP login flow for users not associated with an Identity Provider. Starting in version 0.86.0 and prior to version 1.6.0,… |
| CVE-2026-28506 | Media (4.3) | 0.33% | — | 17 mar 2026 | Outline is a service that allows for collaborative documentation. Prior to 1.5.0, the events.list API endpoint, used for retrieving activity logs, contains a logic flaw in its filtering mechanism. It allows any… |
| CVE-2026-24901 | Alta (8.8) | 0.31% | — | 17 mar 2026 | Outline is a service that allows for collaborative documentation. Prior to 1.4.0, an Insecure Direct Object Reference (IDOR) vulnerability in the document restoration logic allows any team member to unauthorizedly… |
| CVE-2026-25062 | Media (5.5) | 0.42% | — | 11 feb 2026 | Outline is a service that allows for collaborative documentation. Prior to 1.4.0, during the JSON import process, the value of attachments[].key from the imported JSON is passed directly to path.join(rootPath, node.key)… |
| CVE-2025-68663 | Media (6.9) | 0.25% | — | 11 feb 2026 | Outline is a service that allows for collaborative documentation. Prior to 1.1.0, a vulnerability was found in Outline's WebSocket authentication mechanism that allows suspended users to maintain or establish real-time… |
| CVE-2025-64487 | Alta (7.6) | 0.21% | — | 11 feb 2026 | Outline is a service that allows for collaborative documentation. Prior to 1.1.0, a privilege escalation vulnerability exists in the Outline document management system due to inconsistent authorization checks between… |
| CVE-2023-54331 | Alta (8.5) | 0.22% | — | 13 ene 2026 | Outline 1.6.0 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted service path in the… |
| CVE-2025-58351 | Media (6.8) | 0.39% | — | 3 sept 2025 | Outline is a service that allows for collaborative documentation. In versions 0.72.0 through 0.83.0, Outline introduced a feature which facilitates local file system storage capabilities as an optional file storage… |
| CVE-2024-40626 | Media (5.4) | 0.52% | — | 16 jul 2024 | Outline is an open source, collaborative document editor. A type confusion issue was found in ProseMirror’s rendering process that leads to a Stored Cross-Site Scripting (XSS) vulnerability in Outline. An authenticated… |
| CVE-2024-37829 | Alta (8.8) | 0.74% | — | 9 jul 2024 | An issue in Outline <= v0.76.1 allows attackers to execute a session hijacking attack via user interaction with a crafted magic sign-in link. |
| CVE-2024-37830 | Media (6.1) | 0.31% | — | 9 jul 2024 | An issue in Outline <= v0.76.1 allows attackers to redirect a victim user to a malicious site via intercepting and changing the state cookie. |
| CVE-2023-3532 | Media (5.4) | 0.50% | — | 7 jul 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository outline/outline prior to 0.70.1. |
| CVE-2022-2342 | Media (5.4) | 0.70% | — | 7 jul 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository outline/outline prior to v0.64.4. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.