CVE-2024-34710
Status: DeferredHigh (7.1)—
Wiki.js is al wiki app built on Node.js. Client side template injection was discovered, that could allow an attacker to inject malicious JavaScript into the content section of pages that would execute once a victim loads the page that contains the payload. This was possible through the injection of a invalid HTML tag with a template injection payload on the next line. This vulnerability is fixed in 2.5.303.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
- Base score: 7.1
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.40%
- Percentile among all scored CVEs: 31
- Score date: 10/5/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
⚠ AI-inferred from the description — NVD hasn't analyzed this CVE yet, these aren't verified CPEs.
CWEs
- CWE-1336
References
- https://github.com/requarks/wiki/commit/1238d614e1599fefadd4614ee4b5797a087f50ac
- https://github.com/requarks/wiki/security/advisories/GHSA-xjcj-p2qv-q3rf
- https://github.com/requarks/wiki/commit/1238d614e1599fefadd4614ee4b5797a087f50ac
- https://github.com/requarks/wiki/security/advisories/GHSA-xjcj-p2qv-q3rf
Raw JSON (NVD)
Show
{
"id": "CVE-2024-34710",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-34710",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2024-05-21T14:08:35.033091Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.1,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 4.2,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "security-advisories@github.com",
"affectedData": [
{
"vendor": "requarks",
"product": "wiki",
"versions": [
{
"status": "affected",
"version": "<= 2.5.302"
}
]
}
]
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"affectedData": [
{
"cpes": [
"cpe:2.3:a:requarks:wiki.js:-:*:*:*:*:*:*:*"
],
"vendor": "requarks",
"product": "wiki.js",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "custom",
"lessThanOrEqual": "2.5.302"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2024-05-20T22:15:08.500",
"references": [
{
"url": "https://github.com/requarks/wiki/commit/1238d614e1599fefadd4614ee4b5797a087f50ac",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/requarks/wiki/security/advisories/GHSA-xjcj-p2qv-q3rf",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/requarks/wiki/commit/1238d614e1599fefadd4614ee4b5797a087f50ac",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/requarks/wiki/security/advisories/GHSA-xjcj-p2qv-q3rf",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"description": [
{
"lang": "en",
"value": "CWE-1336"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Wiki.js is al wiki app built on Node.js. Client side template injection was discovered, that could allow an attacker to inject malicious JavaScript into the content section of pages that would execute once a victim loads the page that contains the payload. This was possible through the injection of a invalid HTML tag with a template injection payload on the next line. This vulnerability is fixed in 2.5.303.\n"
},
{
"lang": "es",
"value": "Wiki.js es una aplicación wiki construida en Node.js. Se descubrió la inyección de plantilla del lado del cliente, que podría permitir a un atacante inyectar JavaScript malicioso en la sección de contenido de las páginas que se ejecutaría una vez que la víctima carga la página que contiene el payload. Esto fue posible mediante la inyección de una etiqueta HTML no válida con un payload de inyección de plantilla en la siguiente línea. Esta vulnerabilidad se solucionó en 2.5.303."
}
],
"lastModified": "2026-06-17T07:33:55.317",
"sourceIdentifier": "security-advisories@github.com"
}