Cross-site scripting in Wiki.js - #VU151563
Published: September 22, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary JavaScript in a victim's browser session.
The vulnerability exists due to improper neutralization of input during web page generation in the HTML Security renderer when processing page content containing Vue slot directives. A remote user can create a page with a crafted Vue slot directive to execute arbitrary JavaScript in a victim's browser session.
User interaction is required for a victim to view the stored page.