Only the latest version of BookStack is supported. We generally don't support older versions of BookStack due to maintenance effort and since we aim to provide a fairly stable upgrade path for new versions.
If you'd like to be notified of new potential security concerns, you can sign-up to the BookStack security mailing list.
If you've found an issue that likely has no impact on existing users (For example, an issue only in the development branch) feel free to raise it via a standard Codeberg bug report issue.
If the issue could have a security impact on BookStack instances, please directly contact the lead maintainer via email Dan Brown using the details found here.
When contacting us, please note any names (and optionally any profile/company/website links) that you'd like to be used in any attribution within our release notes and content.
Please be patient while the vulnerability is being reviewed. Deploying the fix to address the vulnerability can often take a little time due to the amount of preparation required to ensure the vulnerability has been covered and to create the content required to adequately notify the user-base.
Thank you for keeping BookStack instances safe!
We're generally happy for (and prefer) researchers to raise CVEs for issues they've discovered. We ask that you first confirm with us to ensure the vulnerability is valid and that it hasn't yet been discovered and reported by someone else.
We can raise CVEs ourselves, but we would only go to the effort for security issues with a significant level of risk to users. We typically won't pursue CVEs if there's a lesser level of risk.
Note: Our reporting may change as the Cyber Resilience Act comes into effect.