CVE-2026-24476
EUVD-2026-482426.01.2026, 23:16
Shaarli is a personal bookmarking service. Prior to version 0.16.0, crafting a malicious tag which starting with `"` prematurely ends the `<input>` tag on the start page and allows an attacker to add arbitrary html leading to a possible XSS attack. Version 0.16.0 fixes the issue.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| shaarli_project | shaarli | 𝑥 < 0.16.0 |
𝑥
= Vulnerable software versions
Debian Releases