Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Requarks

First CVE: May 5, 2020Active for: 6 yearsTotal CVEs: 14
27.8
VTI Score
Low

Requarks maintains Wiki.js, a widely deployed open-source wiki platform, where its disclosures cluster around authentication and access-control weaknesses including improper input neutralization, authentication bypass, and path traversal that are characteristic of web application architectures. The vulnerability profile centers on the platform's authentication layer and web-facing request handling, areas where authentication mechanisms and privilege boundaries are frequently the focus of remediation. Live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
14
Total CVEs
More Total CVEs than 94% of tracked vendors
2.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
6.4
Avg CVSS Score
Higher Avg CVSS Score than 39% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Requarks over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 5, 2020
6 years ago
Most Recent CVE
May 12, 2026
73 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (14 CVEs).

14 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-44224HIGH
Wiki.js is an open source wiki app built on Node.js. Prior to 2.5.313, the users.update GraphQL mutation accepts an arbitrary groups array and applies it directly to the database w
May 12, 20268.831NONO
CVE-2025-56643CRITICAL
Requarks Wiki.js 2.5.307 does not properly revoke or invalidate active JWT tokens when a user logs out. As a result, previously issued tokens remain valid and can be reused to acce
Nov 18, 20259.127NONO
CVE-2022-1681HIGH
Authentication Bypass Using an Alternate Path or Channel in GitHub repository requarks/wiki prior to 2.5.281. User can get root user permissions
May 12, 20227.225NONO
CVE-2020-15236HIGH
In Wiki.js before version 2.5.151, directory traversal outside of Wiki.js context is possible when a storage module with local asset cache fetching is enabled. A malicious user can
Oct 5, 20207.525NONO
CVE-2021-43800HIGH
Wiki.js is a wiki app built on Node.js. Prior to version 2.5.254, directory traversal outside of Wiki.js context is possible when a storage module with local asset cache fetching i
Dec 6, 20217.524NONO
CVE-2020-4052MEDIUM
In Wiki.js before 2.4.107, there is a stored cross-site scripting through template injection. This vulnerability exists due to an insecure validation mechanism intended to insert v
Jun 16, 20206.121NONO
CVE-2021-25993MEDIUM
In Requarks wiki.js, versions 2.0.0-beta.147 to 2.5.255 are affected by Stored XSS vulnerability, where a low privileged (editor) user can upload a SVG file that contains malicious
Dec 29, 20215.420NONO
CVE-2021-43855MEDIUM
Wiki.js is a wiki app built on node.js. Wiki.js 2.5.263 and earlier is vulnerable to stored cross-site scripting through a SVG file upload made via a custom request with a fake MIM
Dec 27, 20215.420NONO
CVE-2021-43842MEDIUM
Wiki.js is a wiki app built on Node.js. Wiki.js versions 2.5.257 and earlier are vulnerable to stored cross-site scripting through a SVG file upload. By creating a crafted SVG file
Dec 20, 20215.420NONO
CVE-2020-15274MEDIUM
In Wiki.js before version 2.5.162, an XSS payload can be injected in a page title and executed via the search results. While the title is properly escaped in both the navigation li
Oct 26, 20205.420NONO
View all 14 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products14 CVEs
64%
29%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network14 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (42.9%)
Unknown0 (0.0%)
Required8 (57.1%)
Privileges Required
Low8 (57.1%)
High2 (14.3%)
None4 (28.6%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (14 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Requarks.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Requarks — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Requarks's Products

View all 4 CNAs →

Top CWEs