While only version v0.10.15 was tested and confirmed as vulnerable, status of other versions is unknown since this issue was not addressed by a patch.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 09 Jun 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 09 Jun 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Logseq
Logseq logseq |
|
| Vendors & Products |
Logseq
Logseq logseq |
Tue, 09 Jun 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Logseq is vulnerable to a stored cross-site scripting (XSS). A malicious plugin can include a JavaScript payload in the "name" field of its "package.json" file, which is rendered using "innerHTML" without proper sanitization, allowing the execution of arbitrary code in the privileged host context. While only version v0.10.15 was tested and confirmed as vulnerable, status of other versions is unknown since this issue was not addressed by a patch. | |
| Title | Stored XSS via Unsanitized Plugin Metadata in Logseq | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2026-06-09T14:39:50.413Z
Reserved: 2026-05-20T14:37:51.162Z
Link: CVE-2026-47900
Updated: 2026-06-09T14:39:47.191Z
Status : Deferred
Published: 2026-06-09T14:16:43.700
Modified: 2026-06-09T14:47:47.457
Link: CVE-2026-47900
No data.
OpenCVE Enrichment
Updated: 2026-06-09T16:15:08Z