Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 17 Feb 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:docmost:docmost:*:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Fri, 23 Jan 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Docmost
Docmost docmost |
|
| Vendors & Products |
Docmost
Docmost docmost |
Thu, 22 Jan 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 21 Jan 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Docmost is open-source collaborative wiki and documentation software. In versions 0.3.0 through 0.23.2, Mermaid code block rendering is vulnerable to stored Cross-Site Scripting (XSS). The frontend can render attacker-controlled Mermaid diagrams using mermaid.render(), then inject the returned SVG/HTML into the DOM via dangerouslySetInnerHTML without sanitization. Mermaid per-diagram %%{init}%% directives allow overriding securityLevel and enabling htmlLabels, permitting arbitrary HTML/JS execution for any viewer. This issue has been fixed in version 0.24.0. | |
| Title | Docmost is vulnerable to stored Cross-Site Scripting (XSS) through Mermaid rendering | |
| Weaknesses | CWE-116 CWE-79 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-01-22T16:49:01.024Z
Reserved: 2026-01-14T16:08:37.482Z
Link: CVE-2026-23630
Updated: 2026-01-22T15:09:17.688Z
Status : Analyzed
Published: 2026-01-21T23:15:52.187
Modified: 2026-02-17T16:50:10.463
Link: CVE-2026-23630
No data.
OpenCVE Enrichment
Updated: 2026-04-18T15:45:04Z