Shaarli Project

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 6
    Known Exploited: 0
    0
    Critical Level Threats
    1
    High Level Threats
    5
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-24476

    Shaarli vulnerable to stored XSS via Suggested Tags

    Last Modified: Apr 18, 2026
    Published: Jan 26, 2026

    CVE-2025-55291

    Shaarli allows reflected XSS via searchtags parameter

    Last Modified: Apr 15, 2026
    Published: Aug 18, 2025

    CVE-2023-49469

    Reflected Cross Site Scripting (XSS) vulnerability in Shaarli v0.12.2, allows remote attackers to execute arbitrary code via search tag function.

    Last Modified: Nov 21, 2024
    Published: Dec 28, 2023

    CVE-2013-7351

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in Shaarli allow remote attackers to inject arbitrary web script or HTML via the URL to the (1) showRSS, (2) showATOM, or (3) showDailyRSS function; a (4) file name to the importFile function; or (5) vectors related to bookmarks.

    Last Modified: Nov 21, 2024
    Published: Jan 02, 2020

    CVE-2018-5249

    Cross-site scripting (XSS) vulnerability in Shaarli before 0.8.5 and 0.9.x before 0.9.3 allows remote attackers to inject arbitrary code via the login form's username field (aka the login parameter to the ban_canLogin function in index.php).

    Last Modified: Nov 21, 2024
    Published: Jan 05, 2018
    Items Per Page
    Shaarli_Project Vulnerabilities & Security CVEs | CVE-DB