Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-9fww-8cpr-q66r | Isso affected by Stored XSS via comment website field |
Wed, 25 Feb 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 23 Feb 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Isso-comments
Isso-comments isso |
|
| Vendors & Products |
Isso-comments
Isso-comments isso |
Sat, 21 Feb 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Isso is a lightweight commenting server written in Python and JavaScript. In commits before 0afbfe0691ee237963e8fb0b2ee01c9e55ca2144, there is a stored Cross-Site Scripting (XSS) vulnerability affecting the website and author comment fields. The website field was HTML-escaped using quote=False, which left single and double quotes unescaped. Since the frontend inserts the website value directly into a single-quoted href attribute via string concatenation, a single quote in the URL breaks out of the attribute context, allowing injection of arbitrary event handlers (e.g. onmouseover, onclick). The same escaping is missing entirely from the user-facing comment edit endpoint (PUT /id/) and the moderation edit endpoint (POST /id//edit/). This issue has been patched in commit 0afbfe0691ee237963e8fb0b2ee01c9e55ca2144. To workaround, nabling comment moderation (moderation = enabled = true in isso.cfg) prevents unauthenticated users from publishing comments, raising the bar for exploitation, but it does not fully mitigate the issue since a moderator activating a malicious comment would still expose visitors. | |
| Title | Isso: Stored XSS via comment website field | |
| Weaknesses | CWE-116 CWE-79 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-02-24T18:50:07.650Z
Reserved: 2026-02-19T17:25:31.101Z
Link: CVE-2026-27469
Updated: 2026-02-24T18:50:00.100Z
Status : Deferred
Published: 2026-02-21T08:16:11.993
Modified: 2026-04-15T00:35:42.020
Link: CVE-2026-27469
No data.
OpenCVE Enrichment
Updated: 2026-04-17T17:00:10Z
Github GHSA