Wiki.js
requarks- Product type
- Other
- Catalog vulnerabilities
- 17
Severity across 5 analyzed records
Verify to analyze this security profile
en
As of 09/19/2026, within CyStack's analyzed data, Wiki.js has 3 security vulnerabilities published in the last 90 days. Of these, 2 are rated High or Critical. None of these vulnerabilities is listed in the CISA KEV catalog. CyStack recommends that organizations and individual users remediate applicable vulnerabilities as soon as possible.
CyStack does not yet have sufficient official-source data to identify the latest version of Wiki.js and determine which vulnerabilities affect that version.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan| Vulnerability | Exploitation status | Fix | Published | Severity |
|---|---|---|---|---|
CVE-2026-92776Wiki.js through 2.5.314 Path Prefix Matching Authorization Bypass | Exploitation statusPublic exploit | FixYes | Published09/16/2026 | SeverityHigh |
CVE-2026-92775Wiki.js through 2.5.314 Server-Side Request Forgery via Image Prefetch | Exploitation statusPublic exploit | FixYes | Published09/16/2026 | SeverityHigh |
CVE-2026-92774Wiki.js through 2.5.314 Authorization Bypass via GraphQL Tag Omission | Exploitation statusPublic exploit | FixYes | Published09/16/2026 | SeverityMedium |
CVE-2026-44224Wiki.js: Privilege Escalation via Missing Group Validation in users.update | Exploitation statusPublic exploit | FixYes | Published05/12/2026 | SeverityHigh |
CVE-2025-56643 | Exploitation statusNot known exploited | FixNot confirmed | Published11/18/2025 | SeverityCritical |
CVE-2022-1681Authentication Bypass Using an Alternate Path or Channel in requarks/wiki | Exploitation statusNot confirmed | FixYes | Published05/12/2022 | SeverityHigh |
CVE-2022-23654Improper write access check in Requarks/wiki | Exploitation statusNot known exploited | FixNot confirmed | Published02/22/2022 | SeverityHigh |
CVE-2021-25993Requarks wiki.js - Stored Cross-Site Scripting (XSS) in markdown editor | Exploitation statusPublic exploit | FixYes | Published12/29/2021 | SeverityMedium |
CVE-2021-43855Stored XSS via SVG in Requarks/wiki | Exploitation statusNot confirmed | FixNot confirmed | Published12/27/2021 | SeverityHigh |
CVE-2021-43856Stored XSS in non-image uploads in Requarks/wiki | Exploitation statusNot confirmed | FixNot confirmed | Published12/27/2021 | SeverityHigh |
CVE-2021-43842Stored XSS via SVG file upload in Wiki.js | Exploitation statusNot confirmed | FixNot confirmed | Published12/20/2021 | SeverityMedium |
CVE-2021-43800Asset directory traversal with some storage modules on Windows | Exploitation statusNot confirmed | FixNot confirmed | Published12/06/2021 | SeverityHigh |
CVE-2021-21383XSS in Wiki.js | Exploitation statusNot confirmed | FixNot confirmed | Published03/18/2021 | SeverityHigh |
CVE-2020-15274Stored XSS via search result in Wiki.js | Exploitation statusNot confirmed | FixNot confirmed | Published10/26/2020 | SeverityMedium |
CVE-2020-15236Directory Traversal in Wiki.js | Exploitation statusNot confirmed | FixNot confirmed | Published10/05/2020 | SeverityHigh |
CVE-2020-4052Stored XSS through template injection in Wiki.js | Exploitation statusNot confirmed | FixYes | Published06/16/2020 | SeverityMedium |
CVE-2020-11051XSS in Wiki.js | Exploitation statusNot confirmed | FixYes | Published05/05/2020 | SeverityMedium |