Shaarli Project maintains a lightweight, self-hosted link-sharing and bookmarking application that, despite its narrow scope, serves as a personal knowledge-management tool with a notable user base among privacy-conscious individuals and small communities. The vulnerability profile centers on its single core product and recurs through cross-site scripting weaknesses arising from web-based input handling and output generation. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Shaarli Project over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-7351MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in index.php in Shaarli allow remote attackers to inject arbitrary web script or HTML via the URL to the (1) showRSS, (2) showAT | Jan 2, 2020 | 6.1 | 21 | NO | NO |
CVE-2018-5249MEDIUM Cross-site scripting (XSS) vulnerability in Shaarli before 0.8.5 and 0.9.x before 0.9.3 allows remote attackers to inject arbitrary code via the login form's username field (aka th | Jan 5, 2018 | 6.1 | 21 | NO | NO |
CVE-2026-24476MEDIUM Shaarli is a personal bookmarking service. Prior to version 0.16.0, crafting a malicious tag which starting with `"` prematurely ends the `<input>` tag on the start page and allows | Jan 26, 2026 | 5.4 | 20 | NO | NO |
CVE-2017-15215MEDIUM Reflected XSS vulnerability in Shaarli v0.9.1 allows an unauthenticated attacker to inject JavaScript via the searchtags parameter to index.php. If the victim is an administrator, | Oct 11, 2017 | 6.1 | 20 | NO | NO |
CVE-2023-49469MEDIUM Reflected Cross Site Scripting (XSS) vulnerability in Shaarli v0.12.2, allows remote attackers to execute arbitrary code via search tag function. | Dec 28, 2023 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Shaarli Project.
Media articles that mention a CVE ID that affects a product developed by Shaarli Project — matched by CVE ID, not by vendor name.