SB2020102512 - Cross-site scripting in Wiki.js
Published: October 25, 2020 Updated: April 28, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Cross-site scripting (CVE-ID: CVE-2020-15274)
The vulnerability allows a remote attacker to execute arbitrary script code in a victim's browser.
The vulnerability exists due to cross-site scripting in the search results page when rendering a page title containing crafted script content. A remote attacker can inject a malicious payload into a page title to execute arbitrary script code in a victim's browser.
Remediation
Install update from vendor's website.