MEDIUM 4.4 NVD
CVE-2026-77643
A cross-site scripting vulnerability in queryparser/termgenerator_internal.cc in Xapian xapian-core before 2.1.0 and before 1.4.32 exists due to incomplete HTM
A cross-site scripting vulnerability in
queryparser/termgenerator_internal.cc in Xapian xapian-core before 2.1.0 and before 1.4.32 exists due to incomplete HTML escaping by Xapian::MSet::snippet(). NOTE: this issue exists because of a missed corner case of CVE-2018-0499.
References
- https://bugs.debian.org/1144490
- https://lists.xapian.org/pipermail/xapian-devel/2026-August/003429.html
- https://trac.xapian.org/wiki/SecurityFixes/2018-07-02#a2026-08-13update
This medium severity vulnerability with a CVSS score of 4.4 was published on 2026-08-20 via NVD.
vulnfeed aggregates 9909 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.