Shaarli is a minimalist bookmark manager and link sharing service. Prior to 0.15.0, the input string in the cloud tag page is not properly sanitized. This allows the </title> tag to be prematurely closed, leading to a reflected Cross-Site Scripting (XSS) vulnerability. This vulnerability is fixed in 0.15.0.
Metrics
Affected Vendors & Products
References
History
Thu, 21 Aug 2025 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Shaarli Project
Shaarli Project shaarli |
|
| Vendors & Products |
Shaarli Project
Shaarli Project shaarli |
Mon, 18 Aug 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 18 Aug 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Shaarli is a minimalist bookmark manager and link sharing service. Prior to 0.15.0, the input string in the cloud tag page is not properly sanitized. This allows the </title> tag to be prematurely closed, leading to a reflected Cross-Site Scripting (XSS) vulnerability. This vulnerability is fixed in 0.15.0. | |
| Title | Shaarli allows reflected XSS via searchtags parameter | |
| Weaknesses | CWE-79 CWE-80 CWE-87 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-08-18T17:06:35.799Z
Updated: 2025-08-18T19:56:41.600Z
Reserved: 2025-08-12T16:15:30.237Z
Link: CVE-2025-55291
Updated: 2025-08-18T19:56:18.716Z
Status : Awaiting Analysis
Published: 2025-08-18T17:15:31.243
Modified: 2025-08-18T20:16:28.750
Link: CVE-2025-55291
No data.