Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 14 Sep 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Trilium Notes, version v0.103.0 and earlier, contains a stored cross-site scripting (XSS) vulnerability in the share renderer for webView notes due to improper HTML escaping of user-controlled #webViewSrc values. This vulnerability allows attackers with note-authoring privileges to inject arbitrary JavaScript that executes for any user who opens the shared note, including administrators. | |
| Title | CVE-2026-91021 | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: certcc
Published:
Updated: 2026-09-14T19:41:39.660Z
Reserved: 2026-09-14T17:02:03.736Z
Link: CVE-2026-91021
Updated: 2026-09-14T19:41:27.789Z
Status : Received
Published: 2026-09-14T18:20:29.467
Modified: 2026-09-14T20:17:03.440
Link: CVE-2026-91021
No data.
OpenCVE Enrichment
No data.