PT-2026-32929 · Docmost · Docmost

·

CVE-2026-33193

·

Published

2026-04-14

·

Updated

2026-04-15

CVSS v3.1

4.6

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Docmost versions prior to 0.70.0
Description Docmost is open-source collaborative wiki and documentation software. The software is subject to a stored cross-site scripting (XSS) attack, which occurs when an application includes untrusted data in a web page without proper validation, allowing a malicious script to be permanently stored on the server. This issue is caused by improper handling of MIME type spoofing, where an attacker can misrepresent the file type of an uploaded file to trick the browser into executing it as a script.
Recommendations Update to version 0.70.0.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-33193
GHSA-7CQ4-577P-WP6P

Affected Products

Docmost