CVE-2026-24045: Docmost Affected by Stored XSS in Public Share Page
Docmost is open-source collaborative wiki and documentation software. From 0.20.0 and before 0.25.0, the public share page functionality in Docmost does not properly HTML-escape page titles before inserting them into meta tags and the title tag. This allows Stored Cross-Site Scripting (XSS) attacks, where an attacker can execute arbitrary JavaScript in the context of any user who opens a shared page link. This vulnerability is fixed in 0.25.0.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24045?
The severity of CVE-2026-24045 is classified as high due to the potential for stored cross-site scripting (XSS) attacks.
How do I fix CVE-2026-24045?
To fix CVE-2026-24045, update Docmost to version 0.25.0 or later where the vulnerability is addressed.
What type of vulnerability is CVE-2026-24045?
CVE-2026-24045 is a stored cross-site scripting (XSS) vulnerability affecting the public share page functionality.
Which versions of Docmost are affected by CVE-2026-24045?
Docmost versions prior to 0.25.0 are affected by CVE-2026-24045.
What impact does CVE-2026-24045 have on users?
CVE-2026-24045 can allow attackers to inject malicious scripts into web pages viewed by users, potentially stealing sensitive information.