Requarks

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 15
    Known Exploited: 0
    1
    Critical Level Threats
    8
    High Level Threats
    6
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-44224

    Wiki.js: Privilege Escalation via Missing Group Validation in users.update

    Last Modified: May 14, 2026
    Published: May 12, 2026

    CVE-2025-56643

    Requarks Wiki.js 2.5.307 does not properly revoke or invalidate active JWT tokens when a user logs out. As a result, previously issued tokens remain valid and can be reused to access the system, even after logout. This behavior affects session integrity and may allow unauthorized access if a token is compromised. The issue is present in the authentication resolver logic and affects both the GraphQL endpoint and the logout mechanism.

    Last Modified: Dec 31, 2025
    Published: Nov 18, 2025

    CVE-2024-45298

    Disabled user can bypass lockout by requesting password reset in wiki.js

    Last Modified: Apr 15, 2026
    Published: Sep 18, 2024

    CVE-2022-1681

    Authentication Bypass Using an Alternate Path or Channel in requarks/wiki

    Last Modified: Nov 21, 2024
    Published: May 12, 2022

    CVE-2022-23654

    Improper write access check in Requarks/wiki

    Last Modified: Apr 23, 2025
    Published: Feb 22, 2022
    Items Per Page
    Requarks Vulnerabilities & Security CVEs | CVE-DB