Back to database
Schedule51Medium5.1VulnerabilityCVE-2026-107798No patch link observed

CVE-2026-107798 — jivejdon from commit 595d8d22 through commit ee67a65e contains a stored cross-site scripting vulnerability in the default-enabled TextStyle filter …

Published Oct 8, 2026, 10:17 PM UTCIngested 37m agoSource NVD(cve-db)CVE-2026-107798

Description

jivejdon from commit 595d8d22 through commit ee67a65e contains a stored cross-site scripting vulnerability in the default-enabled TextStyle filter that inserts unvalidated URLs into anchor href attributes. Authenticated attackers can post messages with javascript: links or quote-breaking URLs to execute JavaScript when other users click or hover over rendered links.

CVSS v4.0 base metrics

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
5.1

Medium severity

Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.

AV

Network

Attack Vector

AC

Low

Attack Complexity

AT

None

Attack Requirements

PR

Low

Privileges Required

UI

Passive

User Interaction

VC

Low

Confidentiality (Vulnerable System)

VI

Low

Integrity (Vulnerable System)

VA

None

Availability (Vulnerable System)

SC

Low

Confidentiality (Subsequent System)

SI

Low

Integrity (Subsequent System)

SA

None

Availability (Subsequent System)