ghcr.io/linuxserver/wikijs:version-2.5.201 container image
GitHub Container RegistryScanned 14 Sept 2026
Deployed by 1 of 17,781 indexed charts (latest versions) at this tag.GitHub Container Registry all tags of ghcr.io/linuxserver/wikijs
ghcr.io/linuxserver/wikijs:version-2.5.201 resolved to 58d377933678, scanned 14 Sept 2026: 354 findings, 0 critical; deployed by 1 chart, among them wikijs.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Vulnerabilities
354 distinct on this digest
Findings for digest 58d377933678 as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Medium | GHSA-m974-647v-whv7 | passport-saml | 3.2.2 |
| Medium | ALPINE-CVE-2022-22825 | expat | 2.2.10-r2 |
| Medium | GHSA-pmh2-wpjm-fj45 | mysql2 | 3.9.8 |
| Medium | ALPINE-CVE-2022-23990 | expat | 2.2.10-r3 |
| Medium | GHSA-652h-xwhf-q4h6 | ssh2 | 1.4.0 |
| Medium | GHSA-fwr7-v2mv-hh25 | async | 3.2.2 |
| Medium | ALPINE-CVE-2021-44532 | nodejs | 14.19.0-r0 |
| Medium | GHSA-93q8-gq69-wqmw | ansi-regex | 4.1.1 |
| Medium | ALPINE-CVE-2022-32208 | curl | 7.79.1-r2 |
| Medium | GHSA-6h5x-7c5m-7cr7 | eventsource | 1.1.1 |
| Medium | GHSA-9p95-fxvg-qgq2 | simple-git | 3.15.0 |
| Medium | GHSA-fjxv-7rqg-78g4 | form-data | 2.5.4 |
| Medium | GHSA-wm7h-9275-46v2 | dicer | no fix listed |
| Medium | ALPINE-CVE-2021-44533 | nodejs | 14.19.0-r0 |
| Medium | GHSA-r659-8xfp-j327 | objection | 2.2.16 |
| Medium | GHSA-hgjh-723h-mx2j | url-parse | 1.5.8 |
| Medium | ALPINE-CVE-2022-27775 | curl | 7.79.1-r1 |
| Medium | GHSA-jqv5-7xpx-qj74 | sqlite3 | 5.1.5 |
| Medium | GHSA-74fj-2j2h-c42q | follow-redirects | 1.14.7 |
| Medium | ALPINE-CVE-2022-27782 | curl | 7.79.1-r2 |
| Medium | GHSA-crh6-fp67-6883 | xmldom | no fix listed |
| Medium | ALPINE-CVE-2022-40674 | expat | 2.2.10-r7 |
| Medium | GHSA-c2qf-rxjj-qqgw | semver | 5.7.2 |
| Medium | ALPINE-CVE-2022-27781 | curl | 7.79.1-r2 |
| Medium | GHSA-43fc-jf86-j433 | axios | 0.30.3 |
| Medium | ALPINE-CVE-2021-42380 | busybox | 1.32.1-r7 |
| Medium | ALPINE-CVE-2022-22576 | curl | 7.79.1-r1 |
| Medium | GHSA-r683-j2x4-v87g | node-fetch | 2.6.7 |
| Medium | GHSA-gx9m-whjm-85jf | dompurify | 2.5.0 |
| Medium | ALPINE-CVE-2022-27776 | curl | 7.79.1-r1 |
| Medium | ALPINE-CVE-2021-42379 | busybox | 1.32.1-r7 |
| Medium | ALPINE-CVE-2021-42381 | busybox | 1.32.1-r7 |
| Medium | ALPINE-CVE-2021-42385 | busybox | 1.32.1-r7 |
| Medium | ALPINE-CVE-2022-43680 | expat | 2.2.10-r8 |
| Medium | ALPINE-CVE-2021-42378 | busybox | 1.32.1-r7 |
| Medium | ALPINE-CVE-2021-42382 | busybox | 1.32.1-r7 |
| Medium | ALPINE-CVE-2021-42384 | busybox | 1.32.1-r7 |
| Medium | ALPINE-CVE-2021-42386 | busybox | 1.32.1-r7 |
| Medium | GHSA-qq89-hq3f-393p | tar | 4.4.18 |
| Medium | GHSA-4rch-2fh8-94vw | mysql2 | 3.9.7 |
| Medium | GHSA-q8pj-2vqx-8ggc | css-what | 5.0.1 |
| Medium | GHSA-265q-28rp-chq5 | node-uuid | 1.4.4 |
| Medium | GHSA-pq67-2wwv-3xjx | tar-fs | 2.1.2 |
| Medium | GHSA-qpfw-4m9x-rxx8 | @azure/ | 3.0.8 |
| Medium | GHSA-wf6x-7x77-mvgw | immutable | 3.8.3 |
| Medium | GHSA-rp65-9cf3-cjxr | nth-check | 2.0.1 |
| Medium | ALPINE-CVE-2022-25313 | expat | 2.2.10-r4 |
| Medium | GHSA-8v63-cqqc-6r2c | object-path | 0.11.8 |
| Medium | ALPINE-CVE-2021-41617 | openssh | 8.4_p1-r4 |
| Medium | GHSA-9qrh-qjmc-5w2p | sqlite3 | 5.0.3 |
Used by
1 chart
| Chart | Version | Tag | Containers |
|---|---|---|---|
| wikijsgeek-cookbookVerified publisher | 6.4.2 | version-2.5.201 | 1 |
Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.