VendorsGetoutlineoutlineany version
Vulnerabilities

Getoutline Outline any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

15CVEs
CVE-2026-33640
Outline has a rate limit bypass that allows brute force of email login OTP
Published 2026-03-26 · Analyzed
9.8EPSS 0.005
CVE-2024-37829
An issue in Outline <= v0.76.1 allows attackers to execute a session hijacking attack via user interaction with a crafted magic sign-in link.
Published 2024-07-09 · Analyzed
8.8EPSS 0.007
CVE-2026-24901
Outline's IDOR allows unauthorized viewing and seizing of private deleted drafts
Published 2026-03-17 · Analyzed
8.8EPSS 0.003
CVE-2023-3532
Cross-site Scripting (XSS) - Stored in outline/outline
Published 2023-07-07 · Modified
8.5EPSS 0.005
CVE-2023-54331
Outline 1.6.0 - Unquoted Service Path
Published 2026-01-13 · Modified
8.5EPSS 0.002
CVE-2026-41649
Outline has IDOR in document share creation that allows unauthorized access to private documents across workspaces
Published 2026-04-28 · Analyzed
7.7EPSS 0.004
CVE-2025-64487
Outline is vulnerable to privilege escalation vulnerability in document sharing
Published 2026-02-11 · Analyzed
7.6EPSS 0.002
CVE-2022-2342
Cross-site Scripting (XSS) - Stored in outline/outline
Published 2022-07-07 · Modified
7.3EPSS 0.007
CVE-2024-40626
Stored Cross-site Scripting (XSS) vulnerability in Outline editor
Published 2024-07-16 · Analyzed
7.3EPSS 0.005
CVE-2025-68663
Outline has a suspended user authentication bypass via WebSocket connections
Published 2026-02-11 · Analyzed
6.9EPSS 0.002
CVE-2025-58351
Outline's Local File Storage Feature can Cause CSP Bypass
Published 2025-09-03 · Analyzed
6.8EPSS 0.004
CVE-2026-44695
Outline: Slack OAuth state can link a victim Outline account to an attacker Slack identity
Published 2026-05-11 · Analyzed
6.5EPSS 0.002
CVE-2024-37830
An issue in Outline <= v0.76.1 allows attackers to redirect a victim user to a malicious site via intercepting and changing the state cookie.
Published 2024-07-09 · Modified
6.1EPSS 0.003
CVE-2026-25062
Outline Affected an Arbitrary File Read via Path Traversal in JSON Import
Published 2026-02-11 · Analyzed
5.5EPSS 0.004
CVE-2026-28506
Outline's Information Disclosure in Activity Logs allows User Enumeration of Private Drafts
Published 2026-03-17 · Analyzed
4.3EPSS 0.003