CVE-2026-24476 MEDIUM

CVE-2026-24476: Shaarli vulnerable to stored XSS via Suggested Tags

Vendor Shaarli
Product Shaarli
Weakness CWE-79 · XSS
Published January 26, 2026
Last update January 27, 2026

CVSS base score

5.3/10
Attack vector Local
Attack complexity High
Privileges required High
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Shaarli is a personal bookmarking service. Prior to version 0.16.0, crafting a malicious tag which starting with `"` prematurely ends the `<input>` tag on the start page and allows an attacker to add arbitrary html leading to a possible XSS attack. Version 0.16.0 fixes the issue.

Key dates

02Disclosure timeline

January 26, 2026 CVE published
January 27, 2026 Record updated