CVE-2026-40927: Docmost
Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.
Docmost is open-source collaborative wiki and documentation software. Prior to 0.80.0, when leaving a comment on a page, it is possible to include a JavaScript URI as the link. When a user clicks on the link the JavaScript executes. This vulnerability is fixed in 0.80.0.
Affected products
- Docmost Docmost: before 0.80.0 (fixed in 0.80.0)
Published 2026-04-21. Last modified 2026-06-17.