Requarks maintains Wiki.js, a widely deployed open-source wiki platform, where its disclosures cluster around authentication and access-control weaknesses including improper input neutralization, authentication bypass, and path traversal that are characteristic of web application architectures. The vulnerability profile centers on the platform's authentication layer and web-facing request handling, areas where authentication mechanisms and privilege boundaries are frequently the focus of remediation. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Requarks over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-44224HIGH Wiki.js is an open source wiki app built on Node.js. Prior to 2.5.313, the users.update GraphQL mutation accepts an arbitrary groups array and applies it directly to the database w | May 12, 2026 | 8.8 | 31 | NO | NO |
CVE-2025-56643CRITICAL Requarks Wiki.js 2.5.307 does not properly revoke or invalidate active JWT tokens when a user logs out. As a result, previously issued tokens remain valid and can be reused to acce | Nov 18, 2025 | 9.1 | 27 | NO | NO |
CVE-2022-1681HIGH Authentication Bypass Using an Alternate Path or Channel in GitHub repository requarks/wiki prior to 2.5.281. User can get root user permissions | May 12, 2022 | 7.2 | 25 | NO | NO |
CVE-2020-15236HIGH In Wiki.js before version 2.5.151, directory traversal outside of Wiki.js context is possible when a storage module with local asset cache fetching is enabled. A malicious user can | Oct 5, 2020 | 7.5 | 25 | NO | NO |
CVE-2021-43800HIGH Wiki.js is a wiki app built on Node.js. Prior to version 2.5.254, directory traversal outside of Wiki.js context is possible when a storage module with local asset cache fetching i | Dec 6, 2021 | 7.5 | 24 | NO | NO |
CVE-2020-4052MEDIUM In Wiki.js before 2.4.107, there is a stored cross-site scripting through template injection. This vulnerability exists due to an insecure validation mechanism intended to insert v | Jun 16, 2020 | 6.1 | 21 | NO | NO |
CVE-2021-25993MEDIUM In Requarks wiki.js, versions 2.0.0-beta.147 to 2.5.255 are affected by Stored XSS vulnerability, where a low privileged (editor) user can upload a SVG file that contains malicious | Dec 29, 2021 | 5.4 | 20 | NO | NO |
CVE-2021-43855MEDIUM Wiki.js is a wiki app built on node.js. Wiki.js 2.5.263 and earlier is vulnerable to stored cross-site scripting through a SVG file upload made via a custom request with a fake MIM | Dec 27, 2021 | 5.4 | 20 | NO | NO |
CVE-2021-43842MEDIUM Wiki.js is a wiki app built on Node.js. Wiki.js versions 2.5.257 and earlier are vulnerable to stored cross-site scripting through a SVG file upload. By creating a crafted SVG file | Dec 20, 2021 | 5.4 | 20 | NO | NO |
CVE-2020-15274MEDIUM In Wiki.js before version 2.5.162, an XSS payload can be injected in a page title and executed via the search results. While the title is properly escaped in both the navigation li | Oct 26, 2020 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Requarks.
Media articles that mention a CVE ID that affects a product developed by Requarks — matched by CVE ID, not by vendor name.