CVE-2025-55291

Shaarli is a minimalist bookmark manager and link sharing service. Prior to 0.15.0, the input string in the cloud tag page is not properly sanitized. This allows the </title> tag to be prematurely closed, leading to a reflected Cross-Site Scripting (XSS) vulnerability. This vulnerability is fixed in 0.15.0.
Configurations

No configuration.

History

15 Apr 2026, 00:35

Type Values Removed Values Added
Summary
  • (es) Shaarli es un gestor de marcadores minimalista y un servicio para compartir enlaces. Antes de la versión 0.15.0, la cadena de entrada en la página de etiquetas en la nube no se depuraba correctamente. Esto permitía que la etiqueta se cerrara prematuramente, lo que provocaba una vulnerabilidad de Cross-Site Scripting (XSS) Reflejado. Esta vulnerabilidad se corrigió en la versión 0.15.0.

18 Aug 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-18 17:15

Updated : 2026-04-15 00:35


NVD link : CVE-2025-55291

Mitre link : CVE-2025-55291

CVE.ORG link : CVE-2025-55291


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-80

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)

CWE-87

Improper Neutralization of Alternate XSS Syntax