VendorsRequarkswiki.jsall versions
Vulnerabilities

Requarks Wiki.js

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

14CVEs
CVE-2025-56643
Requarks Wiki.js 2.5.307 does not properly revoke or invalidate active JWT tokens when a user logs out. As a result, previously issued tokens remain valid and can be reused to access the system, even after logout. This behavior affects session integrity and may allow unauthorized access if a token is compromised. The issue is present in the authentication resolver logic and affects both the GraphQL endpoint and the logout mechanism.
Published 2025-11-18 · Analyzed
9.1EPSS 0.004
CVE-2022-1681
Authentication Bypass Using an Alternate Path or Channel in requarks/wiki
Published 2022-05-12 · Modified
9.0EPSS 0.019
CVE-2026-44224
Wiki.js: Privilege Escalation via Missing Group Validation in users.update
Published 2026-05-12 · Analyzed
8.8EPSS 0.006
CVE-2020-15236
Directory Traversal in Wiki.js
Published 2020-10-05 · Modified
8.6EPSS 0.018
CVE-2021-43855
Stored XSS via SVG in Requarks/wiki
Published 2021-12-27 · Modified
8.2EPSS 0.009
CVE-2021-43856
Stored XSS in non-image uploads in Requarks/wiki
Published 2021-12-27 · Modified
8.2EPSS 0.009
CVE-2022-23654
Improper write access check in Requarks/wiki
Published 2022-02-22 · Modified
8.1EPSS 0.007
CVE-2021-21383
XSS in Wiki.js
Published 2021-03-18 · Modified
7.6EPSS 0.009
CVE-2021-43800
Asset directory traversal with some storage modules on Windows
Published 2021-12-06 · Modified
7.5EPSS 0.017
CVE-2020-11051
XSS in Wiki.js
Published 2020-05-05 · Modified
6.9EPSS 0.006
CVE-2020-4052
Stored XSS through template injection in Wiki.js
Published 2020-06-16 · Modified
6.3EPSS 0.008
CVE-2020-15274
Stored XSS via search result in Wiki.js
Published 2020-10-26 · Modified
5.8EPSS 0.008
CVE-2021-43842
Stored XSS via SVG file upload in Wiki.js
Published 2021-12-20 · Modified
5.4EPSS 0.007
CVE-2021-25993
Requarks wiki.js - Stored Cross-Site Scripting (XSS) in markdown editor
Published 2021-12-29 · Modified
5.4EPSS 0.006