Vulnerabilities > Requarks > Wiki JS > 2.1.113

DATE CVE VULNERABILITY TITLE RISK
2022-05-12 CVE-2022-1681 Improper Authentication vulnerability in Requarks Wiki.Js
Authentication Bypass Using an Alternate Path or Channel in GitHub repository requarks/wiki prior to 2.5.281.
network
low complexity
requarks CWE-287
critical
9.0
2022-02-22 CVE-2022-23654 Unspecified vulnerability in Requarks Wiki.Js
Wiki.js is a wiki app built on Node.js.
network
low complexity
requarks
6.5
2021-12-29 CVE-2021-25993 Cross-site Scripting vulnerability in Requarks Wiki.Js
In Requarks wiki.js, versions 2.0.0-beta.147 to 2.5.255 are affected by Stored XSS vulnerability, where a low privileged (editor) user can upload a SVG file that contains malicious JavaScript while uploading assets in the page.
network
requarks CWE-79
3.5
2021-12-27 CVE-2021-43855 Cross-site Scripting vulnerability in Requarks Wiki.Js
Wiki.js is a wiki app built on node.js.
network
requarks CWE-79
3.5
2021-12-27 CVE-2021-43856 Cross-site Scripting vulnerability in Requarks Wiki.Js
Wiki.js is a wiki app built on Node.js.
network
requarks CWE-79
3.5
2021-12-20 CVE-2021-43842 Cross-site Scripting vulnerability in Requarks Wiki.Js
Wiki.js is a wiki app built on Node.js.
network
requarks CWE-79
3.5
2021-12-06 CVE-2021-43800 Path Traversal vulnerability in Requarks Wiki.Js
Wiki.js is a wiki app built on Node.js.
network
requarks CWE-22
4.3
2021-03-18 CVE-2021-21383 Cross-site Scripting vulnerability in Requarks Wiki.Js
Wiki.js an open-source wiki app built on Node.js.
network
requarks CWE-79
3.5
2020-10-26 CVE-2020-15274 Cross-site Scripting vulnerability in Requarks Wiki.Js
In Wiki.js before version 2.5.162, an XSS payload can be injected in a page title and executed via the search results.
network
requarks CWE-79
3.5
2020-06-16 CVE-2020-4052 Cross-site Scripting vulnerability in Requarks Wiki.Js
In Wiki.js before 2.4.107, there is a stored cross-site scripting through template injection.
network
requarks CWE-79
4.3