wikijs Helm chart
geek-cookbookVerified publisherScored 14 Sept 2026
Make documentation a joy to write using Wiki.js's beautiful and intuitive interface!
Latest 6.4.2 4 years agoapp version version-2.5.201 3Artifact Hub
wikijs 6.4.2 deploys 1 container image: ghcr.io/linuxserver/wikijs. Across them, 354 findings — 0 critical, 15 high. The highest contribution is ALPINE-CVE-2022-25236 in expat 2.2.10-r1, fixed in 2.2.10-r4. Chart.yaml declares kubeVersion >=1.16.0-0; rendered for Kubernetes 1.16.0.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
| Image | Tag | Vulnerabilities | Radar Score |
|---|---|---|---|
| ghcr.io/ | version-2.5.201 | 015141198 | 5,946 |
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Vulnerabilities
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | GHSA-mwcw-c2x4-8c55 | nanoid | 3.3.8 |
| Low | GHSA-76mc-f452-cxcm | dompurify | 3.4.7 |
| Low | GHSA-vmf3-w455-68vh | tar | 7.5.16 |
| Low | GHSA-5c9x-8gcm-mpgx | axios | 0.31.1 |
| Low | GHSA-vf2m-468p-8v99 | axios | 0.31.1 |
| Low | GHSA-39q2-94rc-95cp | dompurify | 3.4.0 |
| Low | GHSA-5v7r-6r5c-r473 | file-type | 21.3.1 |
| Low | GHSA-vxvm-qww3-2fh7 | mongodb | 3.6.10 |
| Low | GHSA-cj63-jhhr-wcxv | dompurify | 3.3.2 |
| Low | GHSA-9h6g-pr28-7cqp | nodemailer | 6.9.9 |
| Low | GHSA-f7q4-pwc6-w24p | elliptic | 6.5.7 |
| Low | GHSA-q6x5-8v7m-xcrf | @protobufjs/ | 1.1.1 |
| Low | GHSA-rp9w-3fw7-7cwq | dompurify | 3.4.7 |
| Low | GHSA-2x7j-588g-ccc2 | nodemailer | 9.1.0 |
| Low | GHSA-5p4m-2wfm-xmqj | js-yaml | 3.15.1 |
| Low | GHSA-c27r-x354-4m68 | xml-crypto | 2.0.0 |
| Low | GHSA-qm7x-rc44-rrqw | apollo-server | 2.25.3 |
| Low | GHSA-55q2-fjhq-7xh7 | dompurify | 3.4.13 |
| Low | GHSA-4mjr-xmp4-gh2g | qs | 6.16.0 |
| Low | GHSA-xx6v-rp6x-q39c | axios | 0.31.1 |
| Low | GHSA-898c-q2cr-xwhg | axios | 0.32.0 |
| Low | GHSA-r7g4-qg5f-qqm2 | nodemailer | 8.0.8 |
| Low | GHSA-848j-6mx2-7j84 | elliptic | no fix listed |
| Low | GHSA-268h-hp4c-crq3 | nodemailer | 8.0.9 |
| Low | GHSA-wqvq-jvpq-h66f | nodemailer | 8.0.9 |
| Low | GHSA-cmwh-pvxp-8882 | dompurify | 3.4.11 |
| Low | GHSA-wmmp-3585-3rmp | nodemailer | 9.1.0 |
| Low | GHSA-cjmm-f4jc-qw8r | dompurify | 3.3.2 |
| Low | GHSA-w7fw-mjwx-w883 | qs | 6.14.2 |
| Low | GHSA-9q82-xgwf-vj6h | apollo-server-core | no fix listed |
| Low | GHSA-6rw7-vpxm-498p | qs | 6.14.1 |
| Low | GHSA-v422-hmwv-36x6 | body-parser | 1.20.6 |
| Low | GHSA-8m3c-c648-2xjj | nodemailer | 9.1.1 |
| Low | GHSA-rgwj-5xj2-c3m3 | mysql2 | 3.23.1 |
| Low | GHSA-984p-xq9m-4rjw | express-brute | no fix listed |
| Low | GHSA-v6h2-p8h4-qcjw | brace-expansion | 1.1.12 |
| Low | GHSA-2p3c-p3qw-69r4 | apollo-server | 2.25.4 |
| Low | GHSA-7wwv-vh3v-89cq | highlight.js | 10.4.1 |
| Low | GHSA-v78c-4p63-2j6c | moment-timezone | 0.5.35 |
| Low | GHSA-c7w3-x93f-qmm8 | nodemailer | 8.0.4 |
| Low | GHSA-78xj-cgh5-2h22 | ip | 1.1.9 |
| Low | GHSA-xhjh-pmcv-23jw | axios | 0.31.1 |
| Low | GHSA-qvfw-j98x-7q72 | multer | 2.3.0 |
| Low | GHSA-76c9-3jph-rj3q | on-headers | 1.1.0 |
| Low | GHSA-pxg6-pf52-xh8x | cookie | 0.7.0 |
| Low | GHSA-j965-2qgj-vjmq | aws-sdk | no fix listed |
| Low | GHSA-4x5r-pxfx-6jf8 | @babel/ | 7.29.6 |
| Low | GHSA-vxr8-fq34-vvx9 | dompurify | 3.4.9 |
| Low | GHSA-c2j3-45gr-mqc4 | dompurify | 3.4.12 |
| Low | GHSA-x4vx-rjvf-j5p4 | dompurify | no fix listed |
Indexed versions
| Version | Published | App version | Vulnerabilities | Radar Score |
|---|---|---|---|---|
| 6.4.2latest | 4 years ago | version-2.5.201 | 015141198 | 5,946 |
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.