CVE-2026-40927: Docmost

Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.

Docmost is open-source collaborative wiki and documentation software. Prior to 0.80.0, when leaving a comment on a page, it is possible to include a JavaScript URI as the link. When a user clicks on the link the JavaScript executes. This vulnerability is fixed in 0.80.0.

Affected products

  • Docmost Docmost: before 0.80.0 (fixed in 0.80.0)

Published 2026-04-21. Last modified 2026-06-17.