CVE-2026-48070

CVE-2026-48070 published: Docmost is open-source collaborative wiki and documentation software. Prior to 0.80.1, authenticated users can store attacker-controlled avatarUrl values that are later reused by avatar cleanup without confinement to the intended directory on local-storage ...

View full NVD advisory → ← Back to CVE watch