HIGH 8.8 NVD
CVE-2026-82089
The wallabag (aka fr.gaulupeau.apps.InThePoche) application through 2.6.0 for Android allows XSS because /api/entries data is loaded into a WebView.
The wallabag (aka fr.gaulupeau.apps.InThePoche) application through 2.6.0 for Android allows XSS because /api/entries data is loaded into a WebView.
References
- https://github.com/wallabag/android-app/blob/master/app/src/main/java/fr/gaulupeau/apps/Po
- https://github.com/wallabag/android-app/blob/master/app/src/main/java/fr/gaulupeau/apps/Po
- https://github.com/wallabag/android-app/blob/master/app/src/main/java/fr/gaulupeau/apps/Po
- https://github.com/wallabag/android-app/blob/master/app/src/main/java/fr/gaulupeau/apps/Po
- https://github.com/wallabag/android-app/blob/master/app/src/main/java/fr/gaulupeau/apps/Po
This high severity vulnerability with a CVSS score of 8.8 was published on 2026-08-28 via NVD.
vulnfeed aggregates 11380 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.