CVE-2026-48072Medium· 5.3▾ SunlitDocmost is open-source collaborative wiki and documentation software. Prior to 0.80.1, the public avatar and logo image endpoint accepts attacker-controlled fileName path segments and resolves them against local storage without confineme…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Docmost is open-source collaborative wiki and documentation software. Prior to 0.80.1, the public avatar and logo image endpoint accepts attacker-controlled fileName path segments and resolves them against local storage without confinement to the intended image directory. An unauthenticated attacker can traverse outside the avatar or logo directory and read local storage objects whose final basename satisfies the route's UUID check. This issue is fixed in version 0.80.1.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-48070High· 7.1Docmost is open-source collaborative wiki and documentation software
CVE-2026-48073Medium· 4.3Docmost is open-source collaborative wiki and documentation software
CVE-2026-65827Medium· 6.5Docmost is open-source collaborative wiki and documentation software
CVE-2026-52850Medium· 4.3Docmost is open-source collaborative wiki and documentation software
CVE-2026-52853Medium· 5.2Docmost is open-source collaborative wiki and documentation software
CVE-2023-7260High· 7.5Path Traversal vulnerability discovered in OpenText™ CX-E Voice, affecting all version through 22.4