CVE-2026-48070High· 7.1▾ TwilightDocmost is open-source collaborative wiki and documentation software. Prior to 0.80.1, authenticated users can store attacker-controlled avatarUrl values that are later reused by avatar cleanup without confinement to the intended directo…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 39.1 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Docmost is open-source collaborative wiki and documentation software. Prior to 0.80.1, authenticated users can store attacker-controlled avatarUrl values that are later reused by avatar cleanup without confinement to the intended directory on local-storage deployments. A low-privileged user can cause deletion of arbitrary local files or directories reachable by the Docmost service account. This issue is fixed in version 0.80.1.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-48072Medium· 5.3Docmost is open-source collaborative wiki and documentation software
CVE-2026-48073Medium· 4.3Docmost is open-source collaborative wiki and documentation software
CVE-2026-65827Medium· 6.5Docmost is open-source collaborative wiki and documentation software
CVE-2026-52850Medium· 4.3Docmost is open-source collaborative wiki and documentation software
CVE-2026-52853Medium· 5.2Docmost is open-source collaborative wiki and documentation software
CVE-2023-7260High· 7.5Path Traversal vulnerability discovered in OpenText™ CX-E Voice, affecting all version through 22.4