Bookstackapp maintains a focused documentation and knowledge-management platform whose vulnerability profile reflects its role as a web application handling user content and file uploads. The recurring exposure centers on input-handling and access-control weaknesses including cross-site scripting, improper access control, server-side request forgery, unrestricted file uploads, and path-traversal issues—a characteristic cluster for self-hosted web applications where sanitization boundaries and permission enforcement are critical. While the vendor's footprint is narrowly scoped to a single product, the platform's deployment across organizations as a note-taking and wiki-like system means individual vulnerabilities warrant attention from administrators managing internal instances. Defenders running Bookstackapp should prioritize input validation and upload-handling controls and monitor the vendor's advisories for fixes to these recurring classes. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bookstackapp over time
Signals from CVEs in this vendor scope (21 CVEs).
21 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-4119CRITICAL bookstack is vulnerable to Improper Access Control | Dec 15, 2021 | 9.8 | 45 | NO | NO |
CVE-2020-26211HIGH In BookStack before version 0.30.4, a user with permissions to edit a page could insert JavaScript code through the use of `javascript:` URIs within a link or form which would run, | Nov 3, 2020 | 8.7 | 26 | NO | NO |
CVE-2020-26210HIGH In BookStack before version 0.30.4, a user with permissions to edit a page could add an attached link which would execute untrusted JavaScript code when clicked by a viewer of the | Nov 3, 2020 | 8.7 | 26 | NO | NO |
CVE-2021-4194MEDIUM bookstack is vulnerable to Improper Access Control | Jan 6, 2022 | 6.5 | 23 | NO | NO |
CVE-2021-3944MEDIUM bookstack is vulnerable to Cross-Site Request Forgery (CSRF) | Dec 2, 2021 | 6.8 | 23 | NO | NO |
CVE-2021-3916MEDIUM bookstack is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | Nov 5, 2021 | 6.5 | 23 | NO | NO |
CVE-2021-3906MEDIUM bookstack is vulnerable to Unrestricted Upload of File with Dangerous Type | Oct 27, 2021 | 6.5 | 23 | NO | NO |
CVE-2021-3874MEDIUM bookstack is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | Oct 15, 2021 | 6.5 | 22 | NO | NO |
CVE-2021-3758MEDIUM bookstack is vulnerable to Server-Side Request Forgery (SSRF) | Sep 2, 2021 | 6.5 | 22 | NO | NO |
CVE-2020-5256HIGH BookStack before version 0.25.5 has a vulnerability where a user could upload PHP files through image upload functions, which would allow them to execute code on the host system re | Mar 9, 2020 | 8.8 | 22 | NO | NO |
Signals from CVEs in this vendor scope (21 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bookstackapp.
Media articles that mention a CVE ID that affects a product developed by Bookstackapp — matched by CVE ID, not by vendor name.