Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2026-86285 is a medium-severity vulnerability in BookStack versions 26.05.0, 26.05.1, and 26.05.2. It involves improper access controls in the AttachmentController::getUpdateForm function, allowing remote attackers to manipulate an ID argument to bypass intended access restrictions. A patch identified by commit 4e406c41c4c8060a5795e74c66fb96362e54f400 is available to address this issue. Exploit code is publicly available, but no known active exploitation in the wild has been reported. Join the discussion | CVE Database V5 | 09/07/2026, 08:15:18 UTC Added: 09/07/2026, 08:37:55 UTC |
0 BookStack before 26.05.4 contains a stored cross-site scripting vulnerability in the drawing upload endpoint that accepts unvalidated base64 content and stores it without content inspection. Attackers with editor permissions can upload SVG files containing scripts that execute in administrator browsers when accessed through the image gallery API without content-type validation or CSP headers. Join the discussion | CVE Database V5 | 09/02/2026, 00:37:51 UTC Added: 09/02/2026, 01:22:41 UTC |
BookStack versions before 26.05.4 have an access control vulnerability in the Image Gallery API. Authenticated users with image-update or image-delete permissions can manipulate other users' avatars without proper authorization checks. This occurs due to missing content-type restrictions and improper validation of the avatar's uploaded_to field, allowing attackers to rename, replace, or delete avatars without requiring user-management permissions. Join the discussion | CVE Database V5 | 08/24/2026, 15:33:13 UTC Added: 08/24/2026, 15:52:54 UTC |
A weakness has been identified in BookStackApp BookStack up to 26.03. Affected is the function chapterToMarkdown of the file app/Exports/ExportFormatter.php of the component Chapter Export Handler. Executing a manipulation of the argument pages can lead to improper access controls. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 26.03.1 is able to address this issue. This patch is called 8a59895ba063040cc8dafd82e94024c406df3d04. It is advisable to upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product. Join the discussion | CVE Database V5 | 04/03/2026, 19:45:12 UTC Added: 04/03/2026, 20:00:31 UTC |
0 Incorrect access control in BookStack before v24.05.1 allows attackers to confirm existing system users and perform targeted notification email DoS via public facing forms. Join the discussion | CVE Database V5 | 07/09/2024, 00:00:00 UTC Added: 02/25/2026, 21:40:51 UTC |
Showing 1 to 5 of 5 results