Getoutline develops a single documentation and knowledge-management platform, Outline, that serves collaborative teams and sits in environments where access control and input handling are critical security boundaries. The vendor's vulnerability exposure recurs through application-layer weaknesses including cross-site scripting, authorization bypass, cross-site request forgery, and authentication flaws that are characteristic of web-facing collaboration tools, with a meaningful share reaching serious severity. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Getoutline over time
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-33640CRITICAL Outline is a service that allows for collaborative documentation. Outline implements an Email OTP login flow for users not associated with an Identity Provider. Starting in version | Mar 26, 2026 | 9.8 | 31 | NO | NO |
CVE-2026-24901HIGH Outline is a service that allows for collaborative documentation. Prior to 1.4.0, an Insecure Direct Object Reference (IDOR) vulnerability in the document restoration logic allows | Mar 17, 2026 | 8.8 | 31 | NO | NO |
CVE-2026-41649HIGH Outline is a service that allows for collaborative documentation. The `shares.create` API endpoint starting in version 0.86.0 and prior to version 1.7.0 has an insecure direct obje | Apr 28, 2026 | 7.7 | 30 | NO | NO |
CVE-2026-44695MEDIUM Outline is a service that allows for collaborative documentation. Prior to 1.7.1, the Slack integration callback for GET /auth/slack.post accepts an unsigned, session-independent O | May 11, 2026 | 6.5 | 26 | NO | NO |
CVE-2023-54331HIGH Outline 1.6.0 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated system privileges. Attackers can explo | Jan 13, 2026 | 7.8 | 25 | NO | NO |
CVE-2025-64487HIGH Outline is a service that allows for collaborative documentation. Prior to 1.1.0, a privilege escalation vulnerability exists in the Outline document management system due to incon | Feb 11, 2026 | 7.6 | 24 | NO | NO |
CVE-2024-37829HIGH An issue in Outline <= v0.76.1 allows attackers to execute a session hijacking attack via user interaction with a crafted magic sign-in link. | Jul 9, 2024 | 8.8 | 23 | NO | NO |
CVE-2025-58351MEDIUM Outline is a service that allows for collaborative documentation. In versions 0.72.0 through 0.83.0, Outline introduced a feature which facilitates local file system storage capabi | Sep 3, 2025 | 6.8 | 22 | NO | NO |
CVE-2026-25062MEDIUM Outline is a service that allows for collaborative documentation. Prior to 1.4.0, during the JSON import process, the value of attachments[].key from the imported JSON is passed di | Feb 11, 2026 | 5.5 | 20 | NO | NO |
CVE-2022-2342MEDIUM Cross-site Scripting (XSS) - Stored in GitHub repository outline/outline prior to v0.64.4. | Jul 7, 2022 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Getoutline.
Media articles that mention a CVE ID that affects a product developed by Getoutline — matched by CVE ID, not by vendor name.