Cross-site scripting in Shaarli - #VU151492
Published: September 21, 2026
Vulnerability details
The vulnerability allows a local privileged user to execute arbitrary JavaScript in other users' browsers.
The vulnerability exists due to improper neutralization of input during web page generation in the Picture Wall title rendering of bookmarks when rendering a stored bookmark title on the Picture Wall page. A local privileged user can save a bookmark containing a crafted title to execute arbitrary JavaScript in other users' browsers.
Only bookmarks with generated thumbnails are displayed in the Picture Wall.