CVE-2026-40927 is a stored cross-site scripting (XSS) vulnerability affecting Docmost, an open-source collaborative wiki and documentation platform, in versions prior to 0.80.0. The flaw allows authenticated users to inject malicious JavaScript code through comment links on pages, which executes when other users click the affected links. This vulnerability was patched in version 0.80.0. The vulnerability carries a CVSS 3.1 score of 5.4 (Medium severity) with a network-based attack vector requiring low complexity and user interaction. Exploitation requires valid login credentials and relies on social engineering to convince users to click malicious links. The impact is limited to low-level confidentiality and integrity compromise, with no availability impact. There is no evidence of active exploitation in the wild, and the vulnerability is not listed on the CISA Known Exploited Vulnerabilities catalog. The extremely low EPSS score (0.00029) and inactive hot list status indicate minimal community attention and exploitation likelihood. Organizations running Docmost should prioritize upgrading to version 0.80.0 as a routine maintenance task rather than an emergency response.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.80.0CPE matchmatch criteria | cpe:2.3:a:docmost:docmost:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.