« Volver al listado

Getoutline

Getoutline Outline: vulnerabilidades y CVE

Getoutline Outline tiene 21 vulnerabilidades publicadas, 15 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE21
Últimos 12 meses15
Críticas1
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-54573Media (5.3)0.50%—25 jun 2026
Outline is a service that allows for collaborative documentation. Prior to 1.8.0, the AuthenticationHelper.canAccess function uses ctx.originalUrl to verify if an API key or OAuth token has the required scopes for a…
CVE-2026-44695Media (6.5)0.15%—11 may 2026
Outline is a service that allows for collaborative documentation. Prior to 1.7.1, the Slack integration callback for GET /auth/slack.post accepts an unsigned, session-independent OAuth state value. A third party who can…
CVE-2026-43890Alta (7.7)0.34%—11 may 2026
Outline is a service that allows for collaborative documentation. From 0.84.0 to 1.7.0, the subscriptions.create API endpoint in server/routes/api/subscriptions/subscriptions.ts exhibits a broken authorization pattern.…
CVE-2026-43889Media (6.5)0.35%—11 may 2026
Outline is a service that allows for collaborative documentation. Prior to 1.7.0, the shares.create API accepts both collectionId and documentId simultaneously and, when published=false, only verifies read access for…
CVE-2026-43888Alta (8.7)0.52%—11 may 2026
Outline is a service that allows for collaborative documentation. Prior to 1.7.0, ZipHelper.extract computes the extraction path for each entry by passing a full filesystem path through trimFileAndExt, a filename helper…
CVE-2026-43887Alta (7.3)0.43%—11 may 2026
Outline is a service that allows for collaborative documentation. From 0.84.0 to 1.6.1, the Outline comment section permits users to mention other users; however, the backend does not validate or sanitize the href…
CVE-2026-43886Alta (8.2)0.30%—11 may 2026
Outline is a service that allows for collaborative documentation. From 0.84.0 to 1.6.1, a logic error in OAuthInterface.validateScope() uses Array.some() to validate requested OAuth scopes, causing the function to…
CVE-2026-41649Alta (7.7)0.41%—28 abr 2026
Outline is a service that allows for collaborative documentation. The `shares.create` API endpoint starting in version 0.86.0 and prior to version 1.7.0 has an insecure direct object reference.. When both `collectionId`…
CVE-2026-33640Crítica (9.1)0.55%—26 mar 2026
Outline is a service that allows for collaborative documentation. Outline implements an Email OTP login flow for users not associated with an Identity Provider. Starting in version 0.86.0 and prior to version 1.6.0,…
CVE-2026-28506Media (4.3)0.33%—17 mar 2026
Outline is a service that allows for collaborative documentation. Prior to 1.5.0, the events.list API endpoint, used for retrieving activity logs, contains a logic flaw in its filtering mechanism. It allows any…
CVE-2026-24901Alta (8.8)0.31%—17 mar 2026
Outline is a service that allows for collaborative documentation. Prior to 1.4.0, an Insecure Direct Object Reference (IDOR) vulnerability in the document restoration logic allows any team member to unauthorizedly…
CVE-2026-25062Media (5.5)0.42%—11 feb 2026
Outline is a service that allows for collaborative documentation. Prior to 1.4.0, during the JSON import process, the value of attachments[].key from the imported JSON is passed directly to path.join(rootPath, node.key)…
CVE-2025-68663Media (6.9)0.25%—11 feb 2026
Outline is a service that allows for collaborative documentation. Prior to 1.1.0, a vulnerability was found in Outline's WebSocket authentication mechanism that allows suspended users to maintain or establish real-time…
CVE-2025-64487Alta (7.6)0.21%—11 feb 2026
Outline is a service that allows for collaborative documentation. Prior to 1.1.0, a privilege escalation vulnerability exists in the Outline document management system due to inconsistent authorization checks between…
CVE-2023-54331Alta (8.5)0.22%—13 ene 2026
Outline 1.6.0 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted service path in the…
CVE-2025-58351Media (6.8)0.39%—3 sept 2025
Outline is a service that allows for collaborative documentation. In versions 0.72.0 through 0.83.0, Outline introduced a feature which facilitates local file system storage capabilities as an optional file storage…
CVE-2024-40626Media (5.4)0.52%—16 jul 2024
Outline is an open source, collaborative document editor. A type confusion issue was found in ProseMirror’s rendering process that leads to a Stored Cross-Site Scripting (XSS) vulnerability in Outline. An authenticated…
CVE-2024-37829Alta (8.8)0.74%—9 jul 2024
An issue in Outline <= v0.76.1 allows attackers to execute a session hijacking attack via user interaction with a crafted magic sign-in link.
CVE-2024-37830Media (6.1)0.31%—9 jul 2024
An issue in Outline <= v0.76.1 allows attackers to redirect a victim user to a malicious site via intercepting and changing the state cookie.
CVE-2023-3532Media (5.4)0.50%—7 jul 2023
Cross-site Scripting (XSS) - Stored in GitHub repository outline/outline prior to 0.70.1.
CVE-2022-2342Media (5.4)0.70%—7 jul 2022
Cross-site Scripting (XSS) - Stored in GitHub repository outline/outline prior to v0.64.4.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1210 Exploitation of Remote Services4
  2. T1005 Data from Local System2
  3. T1068 Exploitation for Privilege Escalation2
  4. T1203 Exploitation for Client Execution2
  5. T1059 Command and Scripting Interpreter1
  6. T1059.007 JavaScript1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.