Documize is a document-management and collaboration platform with a focused product footprint centered on its core documentation application. The vendor's vulnerability profile reflects typical web-application input-handling weaknesses, including cross-site scripting and SQL injection flaws arising from improper neutralization of user-supplied data. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Documize over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-23634CRITICAL SQL Injection vulnerability in Documize version 5.4.2, allows remote attackers to execute arbitrary code via the user parameter of the /api/dashboard/activity endpoint. | Dec 29, 2023 | 9.8 | 26 | NO | NO |
CVE-2019-19619MEDIUM domain/section/markdown/markdown.go in Documize before 3.5.1 mishandles untrusted Markdown content. This was addressed by adding the bluemonday HTML sanitizer to defend against XSS | Dec 6, 2019 | 6.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Documize.
Media articles that mention a CVE ID that affects a product developed by Documize — matched by CVE ID, not by vendor name.