Product
getoutline outline
15 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-44695
CVE-2026-41649
CVE-2026-33640
CVE-2026-28506
CVE-2026-24901
CVE-2026-25062
CVE-2025-68663
CVE-2025-64487
CVE-2023-54331
CVE-2025-58351
CVE-2024-40626
CVE-2024-37829
CVE-2024-37830
CVE-2023-3532
CVE-2022-2342
< 1.7.1
Outline is a service that allows for collaborative documentation. Prior to 1.7.1, the Slack integration callback for GET /auth/sla
>= 0.86.0 and < 1.7.0
Outline is a service that allows for collaborative documentation. The
shares.create API endpoint starting in version 0.86.0 and>= 0.86.0 and < 1.6.0
Outline is a service that allows for collaborative documentation. Outline implements an Email OTP login flow for users not associa
< 1.5.0
Outline is a service that allows for collaborative documentation. Prior to 1.5.0, the events.list API endpoint, used for retrievin
< 1.4.0
Outline is a service that allows for collaborative documentation. Prior to 1.4.0, an Insecure Direct Object Reference (IDOR) vulne
< 1.4.0
Outline is a service that allows for collaborative documentation. Prior to 1.4.0, during the JSON import process, the value of att
< 1.1.0
Outline is a service that allows for collaborative documentation. Prior to 1.1.0, a vulnerability was found in Outline's WebSocket
< 1.1.0
Outline is a service that allows for collaborative documentation. Prior to 1.1.0, a privilege escalation vulnerability exists in t
all versions
Outline 1.6.0 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code wi
>= 0.72.0 and < 0.84.0
Outline is a service that allows for collaborative documentation. In versions 0.72.0 through 0.83.0, Outline introduced a feature
< 0.77.3
Outline is an open source, collaborative document editor. A type confusion issue was found in ProseMirror’s rendering process th
<= 0.76.1
An issue in Outline <= v0.76.1 allows attackers to execute a session hijacking attack via user interaction with a crafted magic si
<= 0.76.1
An issue in Outline <= v0.76.1 allows attackers to redirect a victim user to a malicious site via intercepting and changing the st
< 0.70.1
Cross-site Scripting (XSS) - Stored in GitHub repository outline/outline prior to 0.70.1.
< 0.64.4
Cross-site Scripting (XSS) - Stored in GitHub repository outline/outline prior to v0.64.4.