Cross-site scripting in DataEase - CVE-2026-55647
Published: June 18, 2026
DataEase
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary script code in a victim's browser.
The vulnerability exists due to cross-site scripting in the dashboard text components when rendering stored component content with Vue v-html. A remote user can inject crafted HTML with executable event handlers into component data to execute arbitrary script code in a victim's browser.
The issue affects the normal text component and the scrolling text component, and stored payloads can be triggered when another user or an unauthenticated shared-link visitor views the dashboard.