📦 Wiki.js

by Requarks

🔍 What is Wiki.js?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-56643

CRITICAL CVSS 9.1 Nov 18, 2025

Wiki.js 2.5.307 has a critical authentication flaw where JWT tokens remain valid after logout, allowing session hijacking. Attackers can reuse stolen tokens to impersonate users and access sensitive w...

CVE-2022-1681

HIGH CVSS 7.2 May 12, 2022

CVE-2022-1681 is an authentication bypass vulnerability in Wiki.js that allows attackers to gain root user permissions through an alternate path or channel. This affects all users running Wiki.js vers...

CVE-2022-23654

HIGH CVSS 8.1 Feb 22, 2022

Wiki.js versions before 2.5.274 contain an improper authentication vulnerability (CWE-287) where authenticated users with write access to restricted paths can update pages outside their allowed scope....

CVE-2021-43856

HIGH CVSS 8.2 Dec 27, 2021

Wiki.js versions 2.5.263 and earlier are vulnerable to stored cross-site scripting (XSS) through malicious non-image file uploads. An authenticated attacker can upload files like XML that execute Java...

CVE-2021-43800

HIGH CVSS 7.5 Dec 6, 2021

This directory traversal vulnerability in Wiki.js allows attackers to read arbitrary files on Windows systems when specific storage modules are enabled. It affects Wiki.js servers running on Windows w...

CVE-2021-21383

HIGH CVSS 7.6 Mar 18, 2021

Wiki.js versions before 2.5.191 are vulnerable to stored cross-site scripting (XSS) through mustache expressions in code blocks. Malicious users can create crafted wiki pages that execute JavaScript w...