CVE-2021-25993
πΆ mediumSummary
In Requarks wiki.js, versions 2.0.0-beta.147 to 2.5.255 are affected by Stored XSS vulnerability, where a low privileged (editor) user can upload a SVG file that contains malicious JavaScript while uploading assets in the page. That will send the JWT tokens to the attackerβs server and will lead to account takeover when accessed by the victim.
CVSS Score
5.4
Medium
EPSS Score
0.2
Exploit Probability
Published Date
2021-12-29
First Seen: 2026-01-05
π Relative Risk Intelligence
This CVE is Lower Risk - more severe than 22.8% of all 326,604 vulnerabilities in our database.
#252,020
Below average severity
Severity Percentile
π― CISA SSVC Assessment Updated: Apr 30, 2025
π Exploitation Status
Poc
Proof-of-concept available
βοΈ Automatable
NO
Requires human interaction
π₯ Technical Impact
Partial
Limited system impact
π Discovered By
WhiteSource Vulnerability Research Team (WVR)
SSVC data provided by
CISA
Last Modified
2024-11-21
Source
NVD π
CVSS Vector 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CWE IDs (Weakness Types)