VendorsBookStackAppbookstackall versions
Vulnerabilities

BookStackApp BookStack

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

21CVEs
CVE-2021-4119
Improper Access Control in bookstackapp/bookstack
Published 2021-12-15 · Modified
9.8EPSS 0.269
CVE-2020-5256
Remote Code Execution Through Image Uploads in BookStack
Published 2020-03-09 · Modified
9.0EPSS 0.020
CVE-2020-26210
Cross-Site Scripting in BookStack
Published 2020-11-03 · Modified
8.7EPSS 0.012
CVE-2020-26211
Cross-Site Scripting in BookStack
Published 2020-11-03 · Modified
8.7EPSS 0.011
CVE-2021-3915
Unrestricted Upload of File with Dangerous Type in bookstackapp/bookstack
Published 2021-11-13 · Modified
7.6EPSS 0.010
CVE-2022-0877
Cross-site Scripting (XSS) - Stored in bookstackapp/bookstack
Published 2022-03-08 · Modified
7.6EPSS 0.008
CVE-2021-3944
Cross-Site Request Forgery (CSRF) in bookstackapp/bookstack
Published 2021-12-02 · Modified
6.8EPSS 0.006
CVE-2023-6199
Book Stack v23.10.2 - LFR via Blind SSRF
Published 2023-11-20 · Modified
6.5EPSS 0.014
CVE-2021-3916
Path Traversal in bookstackapp/bookstack
Published 2021-11-05 · Modified
6.5EPSS 0.012
CVE-2021-3874
Path Traversal in bookstackapp/bookstack
Published 2021-10-15 · Modified
6.5EPSS 0.012
CVE-2021-4026
Improper Access Control in bookstackapp/bookstack
Published 2021-11-30 · Modified
6.5EPSS 0.009
CVE-2021-3758
Server-Side Request Forgery (SSRF) in bookstackapp/bookstack
Published 2021-09-02 · Modified
6.5EPSS 0.008
CVE-2021-4194
Improper Access Control in bookstackapp/bookstack
Published 2022-01-06 · Modified
6.5EPSS 0.007
CVE-2021-3906
Unrestricted Upload of File with Dangerous Type in bookstackapp/bookstack
Published 2021-10-27 · Modified
6.5EPSS 0.007
CVE-2020-26260
Server Side Request Forgery in BookStack
Published 2020-12-09 · Modified
6.4EPSS 0.008
CVE-2020-11055
Cross-site Scripting in BookStack
Published 2020-05-07 · Modified
6.3EPSS 0.008
CVE-2017-1000462
BookStack version 0.18.4 is vulnerable to stored cross-site scripting, within the page creation page, which can result in disruption of service and execution of javascript code.
Published 2018-01-03 · Modified
5.4EPSS 0.008
CVE-2022-40690
Cross-site scripting vulnerability in BookStack versions prior to v22.09 allows a remote authenticated attacker to inject an arbitrary script.
Published 2022-10-24 · Modified
5.4EPSS 0.007
CVE-2021-3767
Cross-site Scripting (XSS) - Stored in bookstackapp/bookstack
Published 2021-09-06 · Modified
5.4EPSS 0.006
CVE-2021-3768
Cross-site Scripting (XSS) - Stored in bookstackapp/bookstack
Published 2021-09-06 · Modified
5.4EPSS 0.006
CVE-2023-4624
Server-Side Request Forgery (SSRF) in bookstackapp/bookstack
Published 2023-08-30 · Modified
2.4EPSS 0.006