CVE-2026-24045

Docmost is open-source collaborative wiki and documentation software. From g and before 0.25.0, the public share page functionality in Docmost does not properly HTML-escape page titles before inserting them into meta tags and the title tag. This allows Stored Cross-Site Scripting (XSS) attacks, where an attacker can execute arbitrary JavaScript in the context of any user who opens a shared page link. This vulnerability is fixed in 0.25.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:docmost:docmost:*:*:*:*:*:*:*:*

History

25 Feb 2026, 15:04

Type Values Removed Values Added
CPE cpe:2.3:a:docmost:docmost:*:*:*:*:*:*:*:*
First Time Docmost
Docmost docmost
Summary
  • (es) Docmost es un software de wiki y documentación colaborativo de código abierto. Desde g y antes de 0.25.0, la funcionalidad de página compartida pública en Docmost no escapa correctamente los títulos de página HTML antes de insertarlos en las metaetiquetas y la etiqueta de título. Esto permite ataques de cross-site scripting (XSS) almacenado, donde un atacante puede ejecutar JavaScript arbitrario en el contexto de cualquier usuario que abra un enlace de página compartida. Esta vulnerabilidad está corregida en 0.25.0.
References () https://github.com/docmost/docmost/commit/f3f74c591f32f85b8aa9a98ed884a7dd455780f9 - () https://github.com/docmost/docmost/commit/f3f74c591f32f85b8aa9a98ed884a7dd455780f9 - Patch
References () https://github.com/docmost/docmost/releases/tag/v0.25.0 - () https://github.com/docmost/docmost/releases/tag/v0.25.0 - Product, Release Notes
References () https://github.com/docmost/docmost/security/advisories/GHSA-h7fp-4f37-29wq - () https://github.com/docmost/docmost/security/advisories/GHSA-h7fp-4f37-29wq - Exploit, Third Party Advisory

10 Feb 2026, 19:16

Type Values Removed Values Added
References () https://github.com/docmost/docmost/security/advisories/GHSA-h7fp-4f37-29wq - () https://github.com/docmost/docmost/security/advisories/GHSA-h7fp-4f37-29wq -

10 Feb 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-10 18:16

Updated : 2026-02-25 15:04


NVD link : CVE-2026-24045

Mitre link : CVE-2026-24045

CVE.ORG link : CVE-2026-24045


JSON object : View

Products Affected

docmost

  • docmost
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')