MEDIUMVulnerability

CVE-2026-84701

NocoBase fails to sanitize rich text field values in the read renderer, allowing users with create permissions to store malicious HTML with event handlers. Attackers can write arbitrary markup through the collection API that executes in the browsers of all users viewing the affected record.

Properties

severity
MEDIUM
score
5.4
cve_id
CVE-2026-84701
signal_observed_at
2026-09-16T17:34:21+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
published_at
2026-09-02T01:17:25.287
last_modified
2026-09-16T13:42:44.563

Related Entities (2)

HAS_WEAKNESS (1)

[Weakness]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph