CVE-2026-30587 identifies multiple Stored Cross-Site Scripting (XSS) vulnerabilities in Seafile Server versions 13.0.15, 13.0.16-pro, 12.0.14 and prior, specifically within the Seadoc editor due to improper WebSocket message sanitization. Rated 8.7 HIGH (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N), this allows authenticated remote attackers to inject malicious JavaScript via embedded Excalidraw whiteboards or anchor tags. Successful exploitation, which requires user interaction, can lead to high confidentiality and integrity impacts. Currently, there is no evidence of active exploitation, nor are public exploit modules or significant community discussion available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 12.0.20CPE matchmatch criteria | cpe:2.3:a:seafile:seafile_server:*:*:*:*:professional:*:*:* | ||
13.0.15CPE matchmatch criteria | cpe:2.3:a:seafile:seafile_server:13.0.15:*:*:*:community:*:*:* | ||
13.0.16CPE matchmatch criteria | cpe:2.3:a:seafile:seafile_server:13.0.16:*:*:*:professional:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.