CVE-2026-48821 | Shaarli up to 0.16.1 Thumbnail Synchronizer Feature thumbnails-update.js ajaxUpdate cross site scripting (GHSA-mw63-f9qj-c5h3)
A vulnerability was found in Shaarli up to 0.16.1 and classified as problematic. This affects the function ThumbnailsController::ajaxUpdate of the file thumbnails-update.js of the component Thumbnail Synchronizer Feature. The manipulation results in cross site scripting.
This vulnerability was named CVE-2026-48821. The attack may be performed from remote. There is no available exploit.
It is suggested to upgrade the affected component.VulDB Recent EntriesRead More