CVE-2026-28683 is a stored Cross-Site Scripting (XSS) vulnerability affecting Gokapi, a self-hosted file sharing server, prior to version 2.2.3. An authenticated malicious user could upload a specially crafted SVG file and create a hotlink, leading to the execution of arbitrary scripts in a victim's browser. This vulnerability carries a CVSS score of 8.7 (HIGH), indicating a network-based attack with low privileges required, low attack complexity, and high impact on confidentiality and integrity. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered some community discussion, suggesting awareness among security researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.2.3CPE matchmatch criteria | cpe:2.3:a:forceu:gokapi:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.