Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-40927

21
FAUCET Score

CVE-2026-40927 is a stored cross-site scripting (XSS) vulnerability affecting Docmost, an open-source collaborative wiki and documentation platform, in versions prior to 0.80.0. The flaw allows authenticated users to inject malicious JavaScript code through comment links on pages, which executes when other users click the affected links. This vulnerability was patched in version 0.80.0. The vulnerability carries a CVSS 3.1 score of 5.4 (Medium severity) with a network-based attack vector requiring low complexity and user interaction. Exploitation requires valid login credentials and relies on social engineering to convince users to click malicious links. The impact is limited to low-level confidentiality and integrity compromise, with no availability impact. There is no evidence of active exploitation in the wild, and the vulnerability is not listed on the CISA Known Exploited Vulnerabilities catalog. The extremely low EPSS score (0.00029) and inactive hot list status indicate minimal community attention and exploitation likelihood. Organizations running Docmost should prioritize upgrading to version 0.80.0 as a routine maintenance task rather than an emergency response.

Impacted Technologies

VendorProductVersion(s)CPE
< 0.80.0CPE matchmatch criteria
cpe:2.3:a:docmost:docmost:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.4MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
2.3
Impact Score
2.7
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.14%
Probability of exploitation in next 30 days
EPSS Percentile
3.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0014 is in the 1st percentile among its peer group of 15,224 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (1)

github_advisoryvendor investigatingvia nvd_reference
View patch

References

github.com / docmost/docmost/security/advisories/GHSA-4gv6-jw3v-wc34
Vendor Advisory