Stored Cross-Site Scripting in HortusFox by Daniel Brendel
CVE-2026-72559

5.4MEDIUM

Key Information:

Status
Vendor
CVE Published:
11 August 2026

What is CVE-2026-72559?

A stored cross-site scripting (XSS) vulnerability exists in HortusFox 5.9 that allows authenticated users to inject persistent JavaScript into plant notes. This occurs when plant notes are rendered using Parsedown without safe mode. As a result, notes are displayed unescaped in the browsers of all users who access the affected plant. An attacker can exploit this flaw to compromise session cookies and execute actions on behalf of other users, including administrators, significantly jeopardizing user security and data integrity.

Affected Version(s)

HortusFox 0 <= 5.9

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Bobur Abdugafforov
.