bookstack vulnerabilities
CVEs whose affected-version data names the bookstack package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-89022High· 7.4BookStack before 26.05.5 contains an authentication bypass vulnerability in its social login implementation that allows unauthenticated attackers to sign in as arbitrary users by authenticating through a different social provider sharing…
BookStack before 26.05.5 contains an authentication bypass vulnerability in its social login implementation that allows unauthenticated attackers to sign in as arbitrary users by authenticating through a different social provider sharing…
▾ Twilightbookstackapp · bookstackEPSS 0.29%via NVD
CVE-2026-86285Medium· 4.3PoCA vulnerability was detected in BookStack up to 26.05.2
A vulnerability was detected in BookStack up to 26.05.2. Affected by this issue is the function AttachmentController::getUpdateForm of the file app/Uploads/Controllers/AttachmentController.php of the component Attachment Edit Endpoint. T…
▾ TwilightEPSS 0.22%via NVD