Stored Cross-Site Scripting in HortusFox by Daniel Brendel
CVE-2026-72559
5.4MEDIUM
What is CVE-2026-72559?
A stored cross-site scripting (XSS) vulnerability exists in HortusFox 5.9 that allows authenticated users to inject persistent JavaScript into plant notes. This occurs when plant notes are rendered using Parsedown without safe mode. As a result, notes are displayed unescaped in the browsers of all users who access the affected plant. An attacker can exploit this flaw to compromise session cookies and execute actions on behalf of other users, including administrators, significantly jeopardizing user security and data integrity.
Affected Version(s)
HortusFox 0 <= 5.9
