DocumizeCVEs & Vulnerabilities
2 CVEs affecting Documize products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.
2 CVEs→ All vendors
Most Affected Products
documize 2
CVE-2023-23634CRITICAL
SQL Injection vulnerability in Documize version 5.4.2, allows remote attackers to execute arbitrary code via the user parameter of the /api/dashboard/activity endpoint.
29 Dec 2023
9.8
CVSS
CVE-2019-19619MEDIUM
domain/section/markdown/markdown.go in Documize before 3.5.1 mishandles untrusted Markdown content. This was addressed by adding the bluemonday HTML sanitizer to defend against XSS.
6 Dec 2019
6.1
CVSS
← PrevPage 1 / 1Next →