MEDIUM 5.1 NVD
CVE-2026-72743
SQLBot through 1.10.0, fixed in commit c3f40a5, contains a stored cross-site scripting vulnerability in the SQText dashboard component that renders TinyMCE outp
SQLBot through 1.10.0, fixed in commit c3f40a5, contains a stored cross-site scripting vulnerability in the SQText dashboard component that renders TinyMCE output via v-html without sanitization. Attackers who can modify dashboard text widget content can inject arbitrary HTML and JavaScript that executes for all users viewing the dashboard.
References
- https://github.com/dataease/SQLBot/commit/c3f40a5c05a53253b2924765b02b83f6a819948f
- https://github.com/dataease/SQLBot/issues/1308
- https://github.com/dataease/SQLBot/pull/1309
- https://www.vulncheck.com/advisories/sqlbot-sqtext-dashboard-component-stored-xss-via-v-ht
This medium severity vulnerability with a CVSS score of 5.1 was published on 2026-08-10 via NVD.
vulnfeed aggregates 7836 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.