Vulnogram contains a stored cross-site scripting vulnerability in comment hypertext handling
Moderate severity
GitHub Reviewed
Published
Mar 16, 2026
to the GitHub Advisory Database
•
Updated Mar 20, 2026
Description
Published by the National Vulnerability Database
Mar 16, 2026
Published to the GitHub Advisory Database
Mar 16, 2026
Last updated
Mar 20, 2026
Reviewed
Mar 20, 2026
Vulnogram 1.0.0 contains a stored cross-site scripting vulnerability in comment hypertext handling that allows attackers to inject malicious scripts. Remote attackers can inject XSS payloads through comments to execute arbitrary JavaScript in victims' browsers.
References