Description
A cross-site scripting vulnerability in
queryparser/termgenerator_internal.cc in Xapian xapian-core before 2.1.0 and before 1.4.32 exists due to incomplete HTML escaping by Xapian::MSet::snippet(). NOTE: this issue exists because of a missed corner case of CVE-2018-0499.
Published: 2026-08-20
Score: 4.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
Title Cross‑Site Scripting via Incomplete HTML Escaping in Xapian Core Query Parser xapian-core: Xapian xapian-core: Arbitrary code execution via incomplete HTML escaping
References
Metrics threat_severity

None

threat_severity

Moderate


Fri, 21 Aug 2026 01:15:00 +0000

Type Values Removed Values Added
Title Cross‑Site Scripting via Incomplete HTML Escaping in Xapian Core Query Parser

Thu, 20 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Description A cross-site scripting vulnerability in queryparser/termgenerator_internal.cc in Xapian xapian-core before 2.1.0 and before 1.4.32 exists due to incomplete HTML escaping by Xapian::MSet::snippet(). NOTE: this issue exists because of a missed corner case of CVE-2018-0499.
First Time appeared Xapian
Xapian xapian-core
Weaknesses CWE-79
CPEs cpe:2.3:a:xapian:xapian-core:*:*:*:*:*:*:*:*
Vendors & Products Xapian
Xapian xapian-core
References
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Xapian Xapian-core
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-28T18:08:32.929Z

Reserved: 2026-08-20T21:23:30.985Z

Link: CVE-2026-77643

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-20T22:18:06.207

Modified: 2026-08-28T20:19:56.150

Link: CVE-2026-77643

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-20T21:23:31Z

Links: CVE-2026-77643 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T01:00:04Z

Weaknesses