Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Docmost

First CVE: Aug 25, 2025Active for: 1 yearTotal CVEs: 9

Docmost is a modestly represented document collaboration and knowledge management platform that has disclosed vulnerabilities skewing toward serious outcomes. The exposure concentrates in the Docmost application itself and recurs through web application weaknesses—cross-site scripting, authorization bypass and improper authorization, output encoding failures, and path traversal—that are characteristic of user-facing collaboration software handling sensitive documents and access control. Defenders should treat this vendor's patches as relevant to any instances in their environment and monitor for the authorization and input-handling classes that recur here; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
9
Total CVEs
More Total CVEs than 91% of tracked vendors
4.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 97% of tracked vendors
5.8
Avg CVSS Score
Higher Avg CVSS Score than 25% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Docmost over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 25, 2025
10 months ago
Most Recent CVE
Apr 21, 2026
94 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-22249CRITICAL
Docmost is an open-source collaborative wiki and documentation software. From 0.21.0 to before 0.24.0, Docmost is vulnerable to Arbitrary File Write via Zip Import Feature (ZipSlip
Jan 15, 20269.829NONO
CVE-2026-23630MEDIUM
Docmost is open-source collaborative wiki and documentation software. In versions 0.3.0 through 0.23.2, Mermaid code block rendering is vulnerable to stored Cross-Site Scripting (X
Jan 21, 20265.423NONO
CVE-2026-40927MEDIUM
Docmost is open-source collaborative wiki and documentation software. Prior to 0.80.0, when leaving a comment on a page, it is possible to include a JavaScript URI as the link. Whe
Apr 21, 20265.421NONO
CVE-2025-55574MEDIUM
Cross Site Scripting vulnerability in docmost v.0.21.0 and before allows an attacker to execute arbitrary code
Aug 25, 20256.121NONO
CVE-2026-34213MEDIUM
Docmost is open-source collaborative wiki and documentation software. Starting in version 0.3.0 and prior to version 0.71.0, improper authorization in Docmost allows a low-privileg
Apr 14, 20265.420NONO
CVE-2026-34212MEDIUM
Docmost is open-source collaborative wiki and documentation software. In versions prior to 0.71.0, improper neutralization of attachment URLs in Docmost allows a low-privileged aut
Apr 14, 20265.420NONO
CVE-2026-33193MEDIUM
Docmost is open-source collaborative wiki and documentation software. Versions prior to 0.70.0 are vulnerable to a stored cross-site scripting (XSS) attack due to improper handling
Apr 14, 20264.619NONO
CVE-2026-24045MEDIUM
Docmost is open-source collaborative wiki and documentation software. From 0.20.0 and before 0.25.0, the public share page functionality in Docmost does not properly HTML-escape pa
Feb 10, 20265.419NONO
CVE-2026-33146MEDIUM
Docmost is open-source collaborative wiki and documentation software. An authorization bypass vulnerability in versions 0.70.0 through 0.70.2 exposes restricted child page titles a
Apr 14, 20264.318NONO
View all 9 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products9 CVEs
89%
11%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumCritical
Attack Vector
Local0 (0.0%)
Network9 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None2 (22.2%)
Unknown0 (0.0%)
Required7 (77.8%)
Privileges Required
Low6 (66.7%)
High0 (0.0%)
None3 (33.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Docmost.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Docmost — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Docmost's Products

View all 2 CNAs →

Top CWEs