CVE-2026-48821 | Shaarli up to 0.16.1 Thumbnail Synchronizer Feature thumbnails-update.js ajaxUpdate cross site scripting (GHSA-mw63-f9qj-c5h3)

SecurityVulns

A vulnerability was found in Shaarli up to 0.16.1 and classified as problematic. This affects the function ThumbnailsController::ajaxUpdate of the file thumbnails-update.js of the component Thumbnail Synchronizer Feature. The manipulation results in cross site scripting.

This vulnerability was named CVE-2026-48821. The attack may be performed from remote. There is no available exploit.

It is suggested to upgrade the affected component.VulDB Recent EntriesRead More