Vulnerabilities > Bookstackapp > Bookstack > 21.12

DATE CVE VULNERABILITY TITLE RISK
2023-08-30 CVE-2023-4624 Server-Side Request Forgery (SSRF) vulnerability in Bookstackapp Bookstack
Server-Side Request Forgery (SSRF) in GitHub repository bookstackapp/bookstack prior to v23.08.
network
low complexity
bookstackapp CWE-918
2.4
2022-10-24 CVE-2022-40690 Cross-site Scripting vulnerability in Bookstackapp Bookstack
Cross-site scripting vulnerability in BookStack versions prior to v22.09 allows a remote authenticated attacker to inject an arbitrary script.
network
low complexity
bookstackapp CWE-79
5.4
2022-03-08 CVE-2022-0877 Cross-site Scripting vulnerability in Bookstackapp Bookstack
Cross-site Scripting (XSS) - Stored in GitHub repository bookstackapp/bookstack prior to v22.02.3.
3.5
2022-01-06 CVE-2021-4194 Incorrect Authorization vulnerability in Bookstackapp Bookstack
bookstack is vulnerable to Improper Access Control
network
low complexity
bookstackapp CWE-863
4.0