CVE-2024-36676: Bookstackapp Bookstack
High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.
Incorrect access control in BookStack before v24.05.1 allows attackers to confirm existing system users and perform targeted notification email DoS via public facing forms.
Affected products
- Bookstackapp Bookstack: before v24.05.1 (fixed in v24.05.1)
Published 2024-07-09. Last modified 2026-06-17.