๐Ÿ” CVE Alert

CVE-2026-24045

HIGH 7.3

Docmost Affected by Stored XSS in Public Share Page

CVSS Score
7.3
EPSS Score
0.0%
EPSS Percentile
10th

Docmost is open-source collaborative wiki and documentation software. From 0.20.0 and before 0.25.0, the public share page functionality in Docmost does not properly HTML-escape page titles before inserting them into meta tags and the title tag. This allows Stored Cross-Site Scripting (XSS) attacks, where an attacker can execute arbitrary JavaScript in the context of any user who opens a shared page link. This vulnerability is fixed in 0.25.0.

CWE CWE-79
Vendor docmost
Product docmost
Published Feb 10, 2026
Last Updated Apr 14, 2026
Stay Ahead of the Next One

Get instant alerts for docmost docmost

Be the first to know when new high vulnerabilities affecting docmost docmost are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None

Affected Versions

docmost / docmost
>= 0.20.0, < 0.25.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/docmost/docmost/security/advisories/GHSA-h7fp-4f37-29wq github.com: https://github.com/docmost/docmost/commit/f3f74c591f32f85b8aa9a98ed884a7dd455780f9 github.com: https://github.com/docmost/docmost/releases/tag/v0.25.0