CVE-2026-55081
DHIS2 Reflected XSS in OpenAPI HTML scope parameter
DHIS2 is a flexible information system for data capture, management, validation, analytics and visualization. The DHIS2 OpenAPI HTML endpoint reflected values from the `scope` query parameter into the generated HTML document without sufficient sanitization. A crafted `scope` value could be rendered as active HTML or JavaScript in the OpenAPI documentation page. An attacker able to get a user to open a crafted OpenAPI HTML URL could execute JavaScript in that user's browser in the DHIS2 origin. Affected versions: DHIS2 2.42 and 2.43 before the 2026-06-09 security patch releases, and the development branch for DHIS2 2.44 before the fix was merged. Patched in 2.42.5.1, 2.43.0.1, the 2.42 and 2.43 line branches, and the 2.44 development branch.
| CWE | CWE-79 |
| Vendor | dhis2 |
| Product | dhis2-core |
| Published | Jul 21, 2026 |
Get instant alerts for dhis2 dhis2-core
Be the first to know when new unknown vulnerabilities affecting dhis2 dhis2-core are published โ delivered to Slack, Telegram or Discord.