Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

B4Sh2

#50434of 53,624
4.6Total CVSS
Vulnerabilities · 1
PT-2026-32929
4.6
2026-04-14
Docmost · Docmost · CVE-2026-33193
**Name of the Vulnerable Software and Affected Versions** Docmost versions prior to 0.70.0 **Description** Docmost is open-source collaborative wiki and documentation software. The software is subject to a stored cross-site scripting (XSS) attack, which occurs when an application includes untrusted data in a web page without proper validation, allowing a malicious script to be permanently stored on the server. This issue is caused by improper handling of MIME type spoofing, where an attacker can misrepresent the file type of an uploaded file to trick the browser into executing it as a script. **Recommendations** Update to version 0.70.0.