Stored XSS Vulnerability in Shaarli Personal Bookmarking Service by Shaarli
CVE-2026-48823

4.8MEDIUM

Key Information:

Vendor

Shaarli

Status
Vendor
CVE Published:
17 June 2026

What is CVE-2026-48823?

Shaarli, a personal bookmarking service, suffers from a stored Cross-Site Scripting vulnerability in its tag filtering feature. Versions 0.16.1 and earlier allow authenticated users to inject malicious JavaScript code within the tags field when creating or editing a bookmark. This flaw arises due to inadequate sanitization of user inputs in the tags field, enabling the storage of harmful scripts in the database. These scripts are executed when other users interact with the 'Filter by tag' functionality on the homepage, potentially affecting both regular users and administrators. The vulnerability is addressed in version 0.16.2, which ensures proper input sanitization and mitigates the risks associated with this issue.

Affected Version(s)

Shaarli < 0.16.2

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.