bookstackapp
- Total products in the ecosystem
- 2
- Total vulnerabilities (90 days)
- 4
en
Verify to analyze this security profile
As of 09/16/2026, bookstackapp recorded 4 security vulnerabilities in the last 90 days across 1 products, including 3 rated High or above and 0 known exploited vulnerabilities (KEV) that should be prioritized for immediate remediation.
Over the last 90 days, bookstack had the most security vulnerabilities in the bookstackapp ecosystem, with 4 vulnerabilities—approximately 100% of the provider's total vulnerabilities during this period.
| Vulnerability | Exploitation status | Fix | Affected product | Published | Severity |
|---|---|---|---|---|---|
CVE-2026-89022BookStack < 26.05.5 Authentication Bypass via Social Login Provider Confusion | Exploitation statusNot confirmed | FixYes | Affected productbookstack | Published09/15/2026 | SeverityCritical |
CVE-2026-84695BookStack before 26.05.4 Stored XSS via Drawing Upload | Exploitation statusNot known exploited | FixYes | Affected productbookstack | Published09/02/2026 | SeverityCritical |
CVE-2026-82450BookStack before 26.05.4 Remote Code Execution via Book Cover | Exploitation statusNot known exploited | FixYes | Affected productbookstack | Published08/29/2026 | SeverityHigh |
CVE-2026-67204BookStack < 26.05.4 Broken Access Control via Image Gallery API | Exploitation statusNot known exploited | FixYes | Affected productbookstack | Published08/24/2026 | SeverityMedium |
CVE-2026-5484BookStackApp BookStack Chapter Export ExportFormatter.php chapterToMarkdown access control | Exploitation statusPublic exploit | FixYes | Affected productbookstack | Published04/03/2026 | SeverityMedium |
CVE-2023-6199Book Stack v23.10.2 - LFR via Blind SSRF | Exploitation statusNot confirmed | FixNot confirmed | Affected productBookStack | Published11/20/2023 | SeverityMedium |
CVE-2023-4624Server-Side Request Forgery (SSRF) in bookstackapp/bookstack | Exploitation statusPublic exploit | FixYes | Affected productbookstackapp/bookstack | Published08/30/2023 | SeverityLow |
CVE-2022-40690 | Exploitation statusNot known exploited | FixNot confirmed | Affected productBookStack | Published10/24/2022 | SeverityMedium |
CVE-2022-0877Cross-site Scripting (XSS) - Stored in bookstackapp/bookstack | Exploitation statusNot confirmed | FixYes | Affected productbookstackapp/bookstack | Published03/08/2022 | SeverityHigh |
CVE-2021-4194Improper Access Control in bookstackapp/bookstack | Exploitation statusNot confirmed | FixYes | Affected productbookstackapp/bookstack | Published01/06/2022 | SeverityMedium |
CVE-2021-4119Improper Access Control in bookstackapp/bookstack | Exploitation statusNot confirmed | FixYes | Affected productbookstackapp/bookstack | Published12/15/2021 | SeverityMedium |
CVE-2021-3944Cross-Site Request Forgery (CSRF) in bookstackapp/bookstack | Exploitation statusNot confirmed | FixYes | Affected productbookstackapp/bookstack | Published12/02/2021 | SeverityLow |
CVE-2021-4026Improper Access Control in bookstackapp/bookstack | Exploitation statusNot confirmed | FixYes | Affected productbookstackapp/bookstack | Published11/30/2021 | SeverityMedium |
CVE-2021-3915Unrestricted Upload of File with Dangerous Type in bookstackapp/bookstack | Exploitation statusNot confirmed | FixYes | Affected productbookstackapp/bookstack | Published11/13/2021 | SeverityHigh |
CVE-2021-3916Path Traversal in bookstackapp/bookstack | Exploitation statusNot confirmed | FixYes | Affected productbookstackapp/bookstack | Published11/05/2021 | SeverityMedium |
CVE-2021-3906Unrestricted Upload of File with Dangerous Type in bookstackapp/bookstack | Exploitation statusNot confirmed | FixYes | Affected productbookstackapp/bookstack | Published10/27/2021 | SeverityMedium |
CVE-2021-3874Path Traversal in bookstackapp/bookstack | Exploitation statusNot confirmed | FixYes | Affected productbookstackapp/bookstack | Published10/15/2021 | SeverityMedium |
CVE-2021-3768Cross-site Scripting (XSS) - Stored in bookstackapp/bookstack | Exploitation statusNot confirmed | FixYes | Affected productbookstackapp/bookstack | Published09/06/2021 | SeverityMedium |
CVE-2021-3767Cross-site Scripting (XSS) - Stored in bookstackapp/bookstack | Exploitation statusNot confirmed | FixYes | Affected productbookstackapp/bookstack | Published09/06/2021 | SeverityMedium |
CVE-2021-3758Server-Side Request Forgery (SSRF) in bookstackapp/bookstack | Exploitation statusNot confirmed | FixYes | Affected productbookstackapp/bookstack | Published09/02/2021 | SeverityMedium |
CVE-2020-26260Server Side Request Forgery in BookStack | Exploitation statusNot confirmed | FixNot confirmed | Affected productbookstack | Published12/09/2020 | SeverityMedium |
CVE-2020-26211Cross-Site Scripting in BookStack | Exploitation statusNot confirmed | FixYes | Affected productbookstack | Published11/03/2020 | SeverityHigh |
CVE-2020-26210Cross-Site Scripting in BookStack | Exploitation statusNot confirmed | FixYes | Affected productbookstack | Published11/03/2020 | SeverityHigh |
CVE-2020-11055Cross-site Scripting in BookStack | Exploitation statusNot confirmed | FixYes | Affected productbookstack | Published05/07/2020 | SeverityMedium |
CVE-2020-5256Remote Code Execution Through Image Uploads in BookStack | Exploitation statusNot confirmed | FixNot confirmed | Affected productbookstack | Published03/09/2020 | SeverityHigh |
CVE-2017-1000462 | Exploitation statusNot confirmed | FixNot confirmed | Affected productNot confirmed | Published01/03/2018 | SeverityUnknown |
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan