Taguette vulnerable to cross-site scripting via tag name, tag description, document name and document description
Moderate severity
GitHub Reviewed
Published
Oct 20, 2025
in
remram44/taguette
•
Updated Oct 21, 2025
Description
Published by the National Vulnerability Database
Oct 20, 2025
Published to the GitHub Advisory Database
Oct 20, 2025
Reviewed
Oct 20, 2025
Last updated
Oct 21, 2025
Impact
An issue has been discovered in Taguette versions prior to 1.5.0. It was possible for a project member to put JavaScript in name or description fields which would run on project load.
Patches
Users should upgrade to Taguette 1.5.0.
References
References