CVE-2026-24476 Details
Description
Shaarli is a personal bookmarking service. Prior to version 0.16.0, crafting a malicious tag which starting with `"` prematurely ends the `<input>` tag on the start page and allows an attacker to add arbitrary html leading to a possible XSS attack. Version 0.16.0 fixes the issue.
A stored cross-site scripting (XSS) vulnerability has been identified in Shaarli versions prior to 0.16.0. The issue arises from the tag input feature, where a malicious tag starting with a quotation mark can prematurely close the input tag. This flaw allows an attacker to inject arbitrary HTML, potentially leading to an XSS attack. The vulnerability can be exploited by crafting a specific tag and importing it through a Netscape-style bookmarks file, which triggers the XSS payload.
Users can upgrade to Shaarli version 0.16.0 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| shaarli project shaarli | < 0.16.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 17, 2026 | Initial Analysis | [email protected] |
| Jan 26, 2026 | New CVE Received | [email protected] |