๐Ÿ” CVE Alert

CVE-2026-91021

MEDIUM 5.4

CVE-2026-91021

CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th

Trilium Notes, version v0.103.0 and earlier, contains a stored cross-site scripting (XSS) vulnerability in the share renderer for webView notes due to improper HTML escaping of user-controlled #webViewSrc values. This vulnerability allows attackers with note-authoring privileges to inject arbitrary JavaScript that executes for any user who opens the shared note, including administrators.

Vendor trilium
Product trillium notes
Published Sep 14, 2026
Last Updated Sep 14, 2026
Stay Ahead of the Next One

Get instant alerts for trilium trillium notes

Be the first to know when new medium vulnerabilities affecting trilium trillium notes are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Trilium / Trillium Notes
0 โ‰ค v0.103.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vokecyber.com: https://vokecyber.com/research/trilium-share-renderer-stored-xss