Cross-site scripting in Wiki.js - CVE-2021-43856
Published: December 26, 2021 / Updated: April 28, 2026
Wiki.js
Requarks.io
Description
The vulnerability allows a remote user to execute arbitrary JavaScript in another user's browser.
The vulnerability exists due to stored cross-site scripting in non-image file uploads when viewing uploaded files inline in the browser. A remote user can upload a specially crafted file to execute arbitrary JavaScript in another user's browser.
The malicious file must be opened directly by the victim and does not trigger from a normal Wiki.js page.