Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 12 Mar 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Lasuite
Lasuite docs |
|
| CPEs | cpe:2.3:a:lasuite:docs:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Lasuite
Lasuite docs |
Fri, 16 Jan 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Suitenumerique
Suitenumerique docs |
|
| Vendors & Products |
Suitenumerique
Suitenumerique docs |
Thu, 15 Jan 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 15 Jan 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | LaSuite Doc is a collaborative note taking, wiki and documentation platform. From 3.8.0 to 4.3.0, a Stored Cross-Site Scripting (XSS) vulnerability exists in the Interlinking feature. When a user creates a link to another document within the editor, the URL of that link is not validated. An attacker with document editing privileges can inject a malicious javascript: URL that executes arbitrary code when other users click on the link. This vulnerability is fixed in 4.4.0. | |
| Title | LaSuite Doc affected by Stored XSS via Interlinking Block | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-01-15T16:46:57.161Z
Reserved: 2026-01-12T16:20:16.746Z
Link: CVE-2026-22867
Updated: 2026-01-15T16:46:53.561Z
Status : Analyzed
Published: 2026-01-15T17:16:07.883
Modified: 2026-03-12T17:29:40.970
Link: CVE-2026-22867
No data.
OpenCVE Enrichment
Updated: 2026-04-18T06:15:15Z