๐Ÿ” CVE Alert

CVE-2026-63135

HIGH 8.2

YOURLS: Stored XSS in referrer statistics chart via crafted Referer header

CVSS Score
8.2
EPSS Score
0.0%
EPSS Percentile
0th

YOURLS is a self-hosted, customizable URL shortener written in PHP. From 1.5.1 until 1.10.4, YOURLS stores the HTTP Referer header through yourls_get_referrer(), yourls_sanitize_url_safe(), and yourls_log_redirect(), then aggregates the value in yourls-infos.php and passes the derived domain through yourls_get_domain(), yourls_stats_pie(), and yourls_google_array_to_data_table(). The chart builder concatenates labels into inline JavaScript without JavaScript-string escaping, so an unauthenticated attacker can poison the statistics of an existing short URL with a crafted referrer. When an administrator or public stats-page viewer opens the affected statistics page, attacker-controlled JavaScript executes in the YOURLS origin and can access admin-visible data, the API signature token, and privileged same-origin actions. This issue is fixed in version 1.10.4.

CWE CWE-79
Vendor yourls
Product yourls
Published Aug 21, 2026
Stay Ahead of the Next One

Get instant alerts for yourls yourls

Be the first to know when new high vulnerabilities affecting yourls yourls are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
High
Availability
None

Affected Versions

YOURLS / YOURLS
>= 1.5.1, < 1.10.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/YOURLS/YOURLS/security/advisories/GHSA-5h77-88j3-r659 github.com: https://github.com/YOURLS/YOURLS/pull/4107 github.com: https://github.com/YOURLS/YOURLS/commit/e1e93476655107e6caab34e52259eb1c91079ec7 github.com: https://github.com/YOURLS/YOURLS/releases/tag/1.10.4