Cross-site scripting in Wiki.js - CVE-2020-15274
Published: October 25, 2020 / Updated: April 28, 2026
Wiki.js
Requarks.io
Description
The vulnerability allows a remote attacker to execute arbitrary script code in a victim's browser.
The vulnerability exists due to cross-site scripting in the search results page when rendering a page title containing crafted script content. A remote attacker can inject a malicious payload into a page title to execute arbitrary script code in a victim's browser.