CVE-2025-55291: high-severity vulnerability in Shaarli
Shaarli allows reflected XSS via searchtags parameter
Published
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.1epss 0.2%
exploitation probability
0.2%top 87% of all CVEs
observed exploitation
nono source reports it
Shaarli is a minimalist bookmark manager and link sharing service. Prior to 0.15.0, the input string in the cloud tag page is not properly sanitized. This allows the </title> tag to be prematurely closed, leading to a reflected Cross-Site Scripting (XSS) vulnerability. This vulnerability is fixed in 0.15.0.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Affected products
shaarli · ShaarliRelated CVEs — Shaarli
In the same product, most dangerous first.
CVE-2026-50190HIGHShaarli vulnerable to stored XSS via raw bookmark title in document <title> element on public permalink pageEPSS 0.4%CVE-2026-48821MEDIUMShaarli: DOM-based Cross-Site Scripting (XSS) in Thumbnail SynchronizerEPSS 0.2%CVE-2026-24476MEDIUMShaarli vulnerable to stored XSS via Suggested TagsEPSS 0.2%CVE-2026-48822MEDIUMShaarli has Stored Cross-Site Scripting (XSS) via Markdown Reference LinksEPSS 0.2%CVE-2026-48823MEDIUMShaarli has Stored Cross-Site Scripting (XSS) via Tags SearchEPSS 0.2%