Vulnerabilities > Requarks

DATE CVE VULNERABILITY TITLE RISK
2022-05-12 CVE-2022-1681 Improper Authentication vulnerability in Requarks Wiki.Js
Authentication Bypass Using an Alternate Path or Channel in GitHub repository requarks/wiki prior to 2.5.281.
network
low complexity
requarks CWE-287
7.2
2022-02-22 CVE-2022-23654 Unspecified vulnerability in Requarks Wiki.Js
Wiki.js is a wiki app built on Node.js.
network
low complexity
requarks
6.5
2021-12-29 CVE-2021-25993 Cross-site Scripting vulnerability in Requarks Wiki.Js
In Requarks wiki.js, versions 2.0.0-beta.147 to 2.5.255 are affected by Stored XSS vulnerability, where a low privileged (editor) user can upload a SVG file that contains malicious JavaScript while uploading assets in the page.
network
low complexity
requarks CWE-79
5.4
2021-12-27 CVE-2021-43855 Unspecified vulnerability in Requarks Wiki.Js
Wiki.js is a wiki app built on node.js.
network
low complexity
requarks
5.4
2021-12-27 CVE-2021-43856 Cross-site Scripting vulnerability in Requarks Wiki.Js
Wiki.js is a wiki app built on Node.js.
network
low complexity
requarks CWE-79
5.4
2021-12-06 CVE-2021-43800 Path Traversal vulnerability in Requarks Wiki.Js
Wiki.js is a wiki app built on Node.js.
network
low complexity
requarks CWE-22
7.5
2021-03-18 CVE-2021-21383 Unspecified vulnerability in Requarks Wiki.Js
Wiki.js an open-source wiki app built on Node.js.
network
low complexity
requarks
5.4
2020-10-26 CVE-2020-15274 Unspecified vulnerability in Requarks Wiki.Js
In Wiki.js before version 2.5.162, an XSS payload can be injected in a page title and executed via the search results.
network
low complexity
requarks
5.4
2020-10-05 CVE-2020-15236 Unspecified vulnerability in Requarks Wiki.Js
In Wiki.js before version 2.5.151, directory traversal outside of Wiki.js context is possible when a storage module with local asset cache fetching is enabled.
network
low complexity
requarks
7.5
2020-06-16 CVE-2020-4052 Unspecified vulnerability in Requarks Wiki.Js
In Wiki.js before 2.4.107, there is a stored cross-site scripting through template injection.
network
low complexity
requarks
6.1