Cross-site scripting in Shaarli - #VU151492

 

Cross-site scripting in Shaarli - #VU151492

Published: September 21, 2026


Vulnerability identifier: #VU151492
CSH Severity: Low
CVSS v4: 2.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: N/A
CWE-ID: CWE-79
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local privileged user to execute arbitrary JavaScript in other users' browsers.

The vulnerability exists due to improper neutralization of input during web page generation in the Picture Wall title rendering of bookmarks when rendering a stored bookmark title on the Picture Wall page. A local privileged user can save a bookmark containing a crafted title to execute arbitrary JavaScript in other users' browsers.

Only bookmarks with generated thumbnails are displayed in the Picture Wall.


Affected software

Shaarli

Remediation

Install security update from vendor's website.

Shaarli - update to 0.16.7

External References

Related Security Bulletins