Wiki.js 在 2.5.314 及之前版本中存在一个服务器端请求伪造(SSRF)漏洞,该漏洞存在于图像预取渲染器中。该渲染器在获取任意 URL 时,未对协议、主机名或地址进行验证。拥有页面编辑权限的攻击者可以通过注入带有 类的 元素,使服务器向内部服务或云元数据端点发起请求,并将响应返回给攻击者。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-92776 | 8.1 HIGH | Wiki.js through 2.5.314 Path Prefix Matching Authorization Bypass |
| CVE-2026-92774 | 4.3 MEDIUM | Wiki.js through 2.5.314 Authorization Bypass via GraphQL Tag Omission |
No comments yet