๐Ÿ” CVE Alert

CVE-2026-48821

MEDIUM 5.8

Shaarli: DOM-based Cross-Site Scripting (XSS) in Thumbnail Synchronizer

CVSS Score
5.8
EPSS Score
0.0%
EPSS Percentile
0th

Shaarli is a personal bookmarking service. Versions 0.16.1 and prior contain a DOM-based Cross-Site Scripting (XSS) vulnerability in the Thumbnail Synchronizer feature. When an administrator runs the thumbnail update process, malicious bookmark titles are returned via an AJAX response and inserted into the DOM using innerHTML without proper sanitization. The issue originates from the interaction between the backend thumbnail update endpoint and the frontend JavaScript responsible for rendering update progress. On the backend, the ThumbnailsController::ajaxUpdate method returns bookmark data formatted using the 'raw' formatter. This includes the unescaped bookmark title in the JSON response. On the client side, the script thumbnails-update.js processes this AJAX response and dynamically updates the progress interface. Administrators using the thumbnail synchronization feature are affected and exploitation could lead to session hijacking, privilege escalation, backdoor injection and full compromise. This issue has been fixed in version 0.16.2.

CWE CWE-79
Vendor shaarli
Product shaarli
Published Jun 17, 2026
Stay Ahead of the Next One

Get instant alerts for shaarli shaarli

Be the first to know when new medium vulnerabilities affecting shaarli shaarli are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N
Attack Vector
Local
Attack Complexity
Low
Privileges Required
High
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None

Affected Versions

shaarli / Shaarli
< 0.16.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/shaarli/Shaarli/security/advisories/GHSA-mw63-f9qj-c5h3 github.com: https://github.com/shaarli/Shaarli/releases/tag/v0.16.2