Docmost
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 15 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from August 25, 2025 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →Docmost: Page export can include restricted same-space attachments through forged attachmentId
Docmost: Privilege Escalation - ADMIN Can Invite Users as OWNER
Docmost: Public image fileName path traversal leads to unauthorized local file read
Docmost: Broken access control in transclusion lookup API leaks sync-block content across private spaces
Docmost: Unbounded ZIP decompression (zip-bomb) in page import allows denial of service
Docmost: Avatar URL path traversal in avatar cleanup leads to arbitrary local file deletion
Docmost: XSS in Comments with JavaScript URI
Docmost has cross-page attachment overwrite via flawed attachmentId overwrite validation
Docmost page content has stored XSS via unsanitized attachment URLs
GHSL-2026-052: Stored Cross-Site Scripting (XSS) via MIME Type Spoofing in Docmost - CVE-2026-33193
Monitor Docmost in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.