CVE-2020-15274
Estado: ModificadaMedia (5.4)—
In Wiki.js before version 2.5.162, an XSS payload can be injected in a page title and executed via the search results. While the title is properly escaped in both the navigation links and the actual page title, it is not the case in the search results. Commit a57d9af34c15adbf460dde6553d964efddf433de fixes this vulnerability (version 2.5.162) by properly escaping the text content displayed in the search results.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- Puntuación base: 5.4
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.77%
- Percentil entre todas las CVEs puntuadas: 54
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-79
Referencias
- https://docs.requarks.io/releases
- https://github.com/Requarks/wiki/commit/a57d9af34c15adbf460dde6553d964efddf433de
- https://github.com/Requarks/wiki/security/advisories/GHSA-pgjv-84m7-62q7
- https://docs.requarks.io/releases
- https://github.com/Requarks/wiki/commit/a57d9af34c15adbf460dde6553d964efddf433de
- https://github.com/Requarks/wiki/security/advisories/GHSA-pgjv-84m7-62q7
JSON original (NVD)
Mostrar
{
"id": "CVE-2020-15274",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 3.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:S/C:N/I:P/A:N",
"authentication": "SINGLE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "LOW",
"obtainAllPrivilege": false,
"exploitabilityScore": 6.8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 5.8,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "REQUIRED",
"attackComplexity": "HIGH",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 4,
"exploitabilityScore": 1.3
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 5.4,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 2.7,
"exploitabilityScore": 2.3
}
]
},
"affected": [
{
"source": "security-advisories@github.com",
"affectedData": [
{
"vendor": "Requarks",
"product": "wiki.js",
"versions": [
{
"status": "affected",
"version": "< 2.5.162"
}
]
}
]
}
],
"published": "2020-10-26T19:15:12.863",
"references": [
{
"url": "https://docs.requarks.io/releases",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/Requarks/wiki/commit/a57d9af34c15adbf460dde6553d964efddf433de",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/Requarks/wiki/security/advisories/GHSA-pgjv-84m7-62q7",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "security-advisories@github.com"
},
{
"url": "https://docs.requarks.io/releases",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/Requarks/wiki/commit/a57d9af34c15adbf460dde6553d964efddf433de",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/Requarks/wiki/security/advisories/GHSA-pgjv-84m7-62q7",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In Wiki.js before version 2.5.162, an XSS payload can be injected in a page title and executed via the search results. While the title is properly escaped in both the navigation links and the actual page title, it is not the case in the search results. Commit a57d9af34c15adbf460dde6553d964efddf433de fixes this vulnerability (version 2.5.162) by properly escaping the text content displayed in the search results."
},
{
"lang": "es",
"value": "En Wiki.js versiones anteriores a 2.5.162, una carga útil de tipo XSS puede ser inyectada en un título de página y ejecutada por medio de los resultados de búsqueda. Si bien el título se escapa apropiadamente tanto en los enlaces de navegación como en el título de la página real, no es el caso en los resultados de búsqueda. El commit a57d9af34c15adbf460dde6553d964efddf433de corrige esta vulnerabilidad (versión 2.5.162) al escapar apropiadamente el contenido de texto mostrado en los resultados de búsqueda"
}
],
"lastModified": "2026-06-17T02:56:24.357",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:requarks:wiki.js:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A5184AE8-018D-4B51-9320-9F02BD92134F",
"versionEndExcluding": "2.5.162"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security-advisories@github.com"
}