Known Vulnerabilities for BookStack by Na
Listed below are 5 of the newest known vulnerabilities associated with "BookStack" by "Na".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-89022 json | BookStack before 26.05.5 contains an authentication bypass vulnerability in its social login implementation that allows unaut... | Not Provided | 2026-09-15 | 2026-09-15 |
| CVE-2026-86285 json | A vulnerability was detected in BookStack up to 26.05.2. Affected by this issue is the function AttachmentController::getUpda... | Not Provided | 2026-09-07 | 2026-09-09 |
| CVE-2026-84695 json | BookStack before 26.05.4 contains a stored cross-site scripting vulnerability in the drawing upload endpoint that accepts unv... | Not Provided | 2026-09-02 | 2026-09-02 |
| CVE-2026-82450 json | BookStack before 26.05.4 contains a remote code execution vulnerability in the portable ZIP import functionality that allows ... | Not Provided | 2026-08-29 | 2026-08-31 |
| CVE-2026-67204 json | BookStack before 26.05.4 contains a broken access control vulnerability that allows authenticated API users with image-update... | Not Provided | 2026-08-24 | 2026-08-24 |