PT-2026-32929 · Docmost · Docmost

B4Sh2

+1

·

Published

2026-04-14

·

Updated

2026-04-15

·

CVE-2026-33193

CVSS v3.1

4.6

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Docmost versions prior to 0.70.0
Description Docmost is open-source collaborative wiki and documentation software. The software is subject to a stored cross-site scripting (XSS) attack, which occurs when an application includes untrusted data in a web page without proper validation, allowing a malicious script to be permanently stored on the server. This issue is caused by improper handling of MIME type spoofing, where an attacker can misrepresent the file type of an uploaded file to trick the browser into executing it as a script.
Recommendations Update to version 0.70.0.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-33193

Affected Products

Docmost