Vulnerability record · CVE-2020-26210 · published 3 November 2020
CVE-2020-26210: Bookstackapp bookstack cross-site scripting vulnerability
Bookstackapp · Bookstack
In BookStack before version 0.30.4, a user with permissions to edit a page could add an attached link which would execute untrusted JavaScript code when clicked by a viewer of the page. Dangerous content may remain in the database after this update. If you think this could have been exploited the linked advisory provides a SQL query to test. As a workaround, page edit permissions could be limited to only those that are trusted until you can upgrade although this will not address existing exploitation of this vulnerability. The issue is fixed in version 0.30.4.
Description
In BookStack before version 0.30.4, a user with permissions to edit a page could add an attached link which would execute untrusted JavaScript code when clicked by a viewer of the page. Dangerous content may remain in the database after this update. If you think this could have been exploited the linked advisory provides a SQL query to test. As a workaround, page edit permissions could be limited to only those that are trusted until you can upgrade although this will not address existing exploitation of this vulnerability. The issue is fixed in version 0.30.4.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://bookstackapp.com/blog/beta-release-v0-30-4/ | ExploitPatchVendor Advisory |
| https://github.com/BookStackApp/BookStack/commit/349162ea139556b2d25e09e155cec84e21cc9227 | PatchThird Party Advisory |
| https://github.com/BookStackApp/BookStack/releases/tag/v0.30.4 | Third Party Advisory |
| https://github.com/BookStackApp/BookStack/security/advisories/GHSA-7p2j-4h6p-cq3h | ExploitThird Party Advisory |
| https://bookstackapp.com/blog/beta-release-v0-30-4/ | ExploitPatchVendor Advisory |
| https://github.com/BookStackApp/BookStack/commit/349162ea139556b2d25e09e155cec84e21cc9227 | PatchThird Party Advisory |
| https://github.com/BookStackApp/BookStack/releases/tag/v0.30.4 | Third Party Advisory |
| https://github.com/BookStackApp/BookStack/security/advisories/GHSA-7p2j-4h6p-cq3h | ExploitThird Party Advisory |
Track CVE-2020-26210 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-26210), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.