5.4
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Description
CVE-2026-34212 Docmost accepted a javascript: URL inside an attachment node, preserved it through storage and rendering, and turned it back into a clickable anchor in the Docmost origin. Intro I identified, responsibly disclosed, and reproduced a...
Basic Information
ID
0D5ACD84-8796-5644-A05C-46FADC4B35D4
Published
Jun 26, 2026 at 12:41
Modified
Jun 26, 2026 at 12:42