CVE-2025-55574: XSS
Published Aug 25, 2025
·Updated
Cross Site Scripting vulnerability in docmost v.0.21.0 and before allows an attacker to execute arbitrary code
Affected Software
2 affected components
docmost Docmost<0.21.0
docmost Docmost<=0.21.0
Event History
Aug 25, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-55574?
CVE-2025-55574 is classified as a critical severity Cross Site Scripting vulnerability.
2
How do I fix CVE-2025-55574?
To fix CVE-2025-55574, upgrade Docmost to version 0.21.1 or later where the vulnerability is resolved.
3
What impact does CVE-2025-55574 have on affected systems?
CVE-2025-55574 allows attackers to execute arbitrary code, potentially leading to data compromise or system takeover.
4
Which versions of Docmost are affected by CVE-2025-55574?
Docmost versions up to and including 0.21.0 are affected by CVE-2025-55574.
5
Is CVE-2025-55574 easy to exploit?
Yes, CVE-2025-55574 can be easily exploited by attackers with basic skills, making it a significant threat.