Wiki.Js
Vendor:
First CVE: May 5, 2020 · Active for 6 years
14
Total CVEs
More Total CVEs than 91% of tracked products
2.8
Avg CVEs / Year
Higher CVE frequency than 75% of tracked products
6.4
Avg CVSS
Higher Avg CVSS than 28% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Wiki.Js over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 5, 2020
6 years ago
Most Recent CVE
May 12, 2026
73 days ago
CVE Severity & Scoring
Wiki.Js14 CVEs
64%
29%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network14 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (42.9%)
Unknown0 (0.0%)
Required8 (57.1%)
Privileges Required
Low8 (57.1%)
High2 (14.3%)
None4 (28.6%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-44224HIGH Wiki.js is an open source wiki app built on Node.js. Prior to 2.5.313, the users.update GraphQL mutation accepts an arbitrary groups array and applies it directly to the database w | May 12, 2026 | 8.8 | 31 | NO | NO |
CVE-2025-56643CRITICAL Requarks Wiki.js 2.5.307 does not properly revoke or invalidate active JWT tokens when a user logs out. As a result, previously issued tokens remain valid and can be reused to acce | Nov 18, 2025 | 9.1 | 27 | NO | NO |
CVE-2022-1681HIGH Authentication Bypass Using an Alternate Path or Channel in GitHub repository requarks/wiki prior to 2.5.281. User can get root user permissions | May 12, 2022 | 7.2 | 25 | NO | NO |
CVE-2020-15236HIGH In Wiki.js before version 2.5.151, directory traversal outside of Wiki.js context is possible when a storage module with local asset cache fetching is enabled. A malicious user can | Oct 5, 2020 | 7.5 | 25 | NO | NO |
CVE-2021-43800HIGH Wiki.js is a wiki app built on Node.js. Prior to version 2.5.254, directory traversal outside of Wiki.js context is possible when a storage module with local asset cache fetching i | Dec 6, 2021 | 7.5 | 24 | NO | NO |
CVE-2020-4052MEDIUM In Wiki.js before 2.4.107, there is a stored cross-site scripting through template injection. This vulnerability exists due to an insecure validation mechanism intended to insert v | Jun 16, 2020 | 6.1 | 21 | NO | NO |
CVE-2021-25993MEDIUM In Requarks wiki.js, versions 2.0.0-beta.147 to 2.5.255 are affected by Stored XSS vulnerability, where a low privileged (editor) user can upload a SVG file that contains malicious | Dec 29, 2021 | 5.4 | 20 | NO | NO |
CVE-2021-43855MEDIUM Wiki.js is a wiki app built on node.js. Wiki.js 2.5.263 and earlier is vulnerable to stored cross-site scripting through a SVG file upload made via a custom request with a fake MIM | Dec 27, 2021 | 5.4 | 20 | NO | NO |
CVE-2021-43842MEDIUM Wiki.js is a wiki app built on Node.js. Wiki.js versions 2.5.257 and earlier are vulnerable to stored cross-site scripting through a SVG file upload. By creating a crafted SVG file | Dec 20, 2021 | 5.4 | 20 | NO | NO |
CVE-2020-15274MEDIUM In Wiki.js before version 2.5.162, an XSS payload can be injected in a page title and executed via the search results. While the title is properly escaped in both the navigation li | Oct 26, 2020 | 5.4 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (14 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (14 CVEs).
Media Mentions
Signals from CVEs in this product scope (14 CVEs).
Top CNAs Publishing CVEs For Wiki.Js
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.5.307 | 1 | 9.1 | 0.4% | 0 | 0 |
| 2.0.0 | 1 | 5.4 | 0.6% | 0 | 0 |