Docmost is a modestly represented document collaboration and knowledge management platform that has disclosed vulnerabilities skewing toward serious outcomes. The exposure concentrates in the Docmost application itself and recurs through web application weaknesses—cross-site scripting, authorization bypass and improper authorization, output encoding failures, and path traversal—that are characteristic of user-facing collaboration software handling sensitive documents and access control. Defenders should treat this vendor's patches as relevant to any instances in their environment and monitor for the authorization and input-handling classes that recur here; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Docmost over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-22249CRITICAL Docmost is an open-source collaborative wiki and documentation software. From 0.21.0 to before 0.24.0, Docmost is vulnerable to Arbitrary File Write via Zip Import Feature (ZipSlip | Jan 15, 2026 | 9.8 | 29 | NO | NO |
CVE-2026-23630MEDIUM Docmost is open-source collaborative wiki and documentation software. In versions 0.3.0 through 0.23.2, Mermaid code block rendering is vulnerable to stored Cross-Site Scripting (X | Jan 21, 2026 | 5.4 | 23 | NO | NO |
CVE-2026-40927MEDIUM Docmost is open-source collaborative wiki and documentation software. Prior to 0.80.0, when leaving a comment on a page, it is possible to include a JavaScript URI as the link. Whe | Apr 21, 2026 | 5.4 | 21 | NO | NO |
CVE-2025-55574MEDIUM Cross Site Scripting vulnerability in docmost v.0.21.0 and before allows an attacker to execute arbitrary code | Aug 25, 2025 | 6.1 | 21 | NO | NO |
CVE-2026-34213MEDIUM Docmost is open-source collaborative wiki and documentation software. Starting in version 0.3.0 and prior to version 0.71.0, improper authorization in Docmost allows a low-privileg | Apr 14, 2026 | 5.4 | 20 | NO | NO |
CVE-2026-34212MEDIUM Docmost is open-source collaborative wiki and documentation software. In versions prior to 0.71.0, improper neutralization of attachment URLs in Docmost allows a low-privileged aut | Apr 14, 2026 | 5.4 | 20 | NO | NO |
CVE-2026-33193MEDIUM Docmost is open-source collaborative wiki and documentation software. Versions prior to 0.70.0 are vulnerable to a stored cross-site scripting (XSS) attack due to improper handling | Apr 14, 2026 | 4.6 | 19 | NO | NO |
CVE-2026-24045MEDIUM Docmost is open-source collaborative wiki and documentation software. From 0.20.0 and before 0.25.0, the public share page functionality in Docmost does not properly HTML-escape pa | Feb 10, 2026 | 5.4 | 19 | NO | NO |
CVE-2026-33146MEDIUM Docmost is open-source collaborative wiki and documentation software. An authorization bypass vulnerability in versions 0.70.0 through 0.70.2 exposes restricted child page titles a | Apr 14, 2026 | 4.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Docmost.
Media articles that mention a CVE ID that affects a product developed by Docmost — matched by CVE ID, not by vendor name.