PT-2026-32929 · Docmost · Docmost
B4Sh2
+1
·
Published
2026-04-14
·
Updated
2026-04-15
·
CVE-2026-33193
CVSS v3.1
4.6
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Docmost versions prior to 0.70.0
Description
Docmost is open-source collaborative wiki and documentation software. The software is subject to a stored cross-site scripting (XSS) attack, which occurs when an application includes untrusted data in a web page without proper validation, allowing a malicious script to be permanently stored on the server. This issue is caused by improper handling of MIME type spoofing, where an attacker can misrepresent the file type of an uploaded file to trick the browser into executing it as a script.
Recommendations
Update to version 0.70.0.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Docmost