Docmost
Vendor:
First CVE: Aug 25, 2025 · Active for under a year
9
Total CVEs
More Total CVEs than 86% of tracked products
4.5
Avg CVEs / Year
Higher CVE frequency than 86% of tracked products
5.8
Avg CVSS
Higher Avg CVSS than 17% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Docmost over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 25, 2025
10 months ago
Most Recent CVE
Apr 21, 2026
94 days ago
CVE Severity & Scoring
Docmost9 CVEs
89%
11%
All CVEs352,231 CVEs
45%
40%
11%
MediumCritical
Attack Vector
Local0 (0.0%)
Network9 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None2 (22.2%)
Unknown0 (0.0%)
Required7 (77.8%)
Privileges Required
Low6 (66.7%)
High0 (0.0%)
None3 (33.3%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-22249CRITICAL Docmost is an open-source collaborative wiki and documentation software. From 0.21.0 to before 0.24.0, Docmost is vulnerable to Arbitrary File Write via Zip Import Feature (ZipSlip | Jan 15, 2026 | 9.8 | 29 | NO | NO |
CVE-2026-23630MEDIUM Docmost is open-source collaborative wiki and documentation software. In versions 0.3.0 through 0.23.2, Mermaid code block rendering is vulnerable to stored Cross-Site Scripting (X | Jan 21, 2026 | 5.4 | 23 | NO | NO |
CVE-2026-40927MEDIUM Docmost is open-source collaborative wiki and documentation software. Prior to 0.80.0, when leaving a comment on a page, it is possible to include a JavaScript URI as the link. Whe | Apr 21, 2026 | 5.4 | 21 | NO | NO |
CVE-2025-55574MEDIUM Cross Site Scripting vulnerability in docmost v.0.21.0 and before allows an attacker to execute arbitrary code | Aug 25, 2025 | 6.1 | 21 | NO | NO |
CVE-2026-34213MEDIUM Docmost is open-source collaborative wiki and documentation software. Starting in version 0.3.0 and prior to version 0.71.0, improper authorization in Docmost allows a low-privileg | Apr 14, 2026 | 5.4 | 20 | NO | NO |
CVE-2026-34212MEDIUM Docmost is open-source collaborative wiki and documentation software. In versions prior to 0.71.0, improper neutralization of attachment URLs in Docmost allows a low-privileged aut | Apr 14, 2026 | 5.4 | 20 | NO | NO |
CVE-2026-33193MEDIUM Docmost is open-source collaborative wiki and documentation software. Versions prior to 0.70.0 are vulnerable to a stored cross-site scripting (XSS) attack due to improper handling | Apr 14, 2026 | 4.6 | 19 | NO | NO |
CVE-2026-24045MEDIUM Docmost is open-source collaborative wiki and documentation software. From 0.20.0 and before 0.25.0, the public share page functionality in Docmost does not properly HTML-escape pa | Feb 10, 2026 | 5.4 | 19 | NO | NO |
CVE-2026-33146MEDIUM Docmost is open-source collaborative wiki and documentation software. An authorization bypass vulnerability in versions 0.70.0 through 0.70.2 exposes restricted child page titles a | Apr 14, 2026 | 4.3 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (9 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (9 CVEs).
Media Mentions
Signals from CVEs in this product scope (9 CVEs).
Top CNAs Publishing CVEs For Docmost
Top CWEs
Versions
No cataloged versions.