wiki
requarks- Product type
- Other
- Catalog vulnerabilities
- 11
Severity across 11 analyzed records
Verify to analyze this security profile
en
As of 09/19/2026, within CyStack's analyzed data, wiki has 0 security vulnerabilities published in the last 90 days. Of these, 0 are rated High or Critical. None of these vulnerabilities is listed in the CISA KEV catalog. CyStack recommends that organizations and individual users remediate applicable vulnerabilities as soon as possible.
CyStack does not yet have sufficient official-source data to identify the latest version of wiki and determine which vulnerabilities affect that version.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan| Vulnerability | Exploitation status | Fix | Published | Severity |
|---|---|---|---|---|
CVE-2026-44224Wiki.js: Privilege Escalation via Missing Group Validation in users.update | Exploitation statusPublic exploit | FixYes | Published05/12/2026 | SeverityHigh |
CVE-2024-45298Disabled user can bypass lockout by requesting password reset in wiki.js | Exploitation statusPublic exploit | FixNot confirmed | Published09/18/2024 | SeverityMedium |
CVE-2024-34710Wiki.js Stored XSS through Client Side Template Injection | Exploitation statusPublic exploit | FixYes | Published05/20/2024 | SeverityHigh |
CVE-2022-23654Improper write access check in Requarks/wiki | Exploitation statusNot known exploited | FixNot confirmed | Published02/22/2022 | SeverityHigh |
CVE-2021-25993Requarks wiki.js - Stored Cross-Site Scripting (XSS) in markdown editor | Exploitation statusPublic exploit | FixYes | Published12/29/2021 | SeverityMedium |
CVE-2021-43855Stored XSS via SVG in Requarks/wiki | Exploitation statusNot confirmed | FixNot confirmed | Published12/27/2021 | SeverityHigh |
CVE-2021-43856Stored XSS in non-image uploads in Requarks/wiki | Exploitation statusNot confirmed | FixNot confirmed | Published12/27/2021 | SeverityHigh |
CVE-2021-43842Stored XSS via SVG file upload in Wiki.js | Exploitation statusNot confirmed | FixNot confirmed | Published12/20/2021 | SeverityMedium |
CVE-2021-43800Asset directory traversal with some storage modules on Windows | Exploitation statusNot confirmed | FixNot confirmed | Published12/06/2021 | SeverityHigh |
CVE-2021-21383XSS in Wiki.js | Exploitation statusNot confirmed | FixNot confirmed | Published03/18/2021 | SeverityHigh |
CVE-2020-15236Directory Traversal in Wiki.js | Exploitation statusNot confirmed | FixNot confirmed | Published10/05/2020 | SeverityHigh |