Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-j8j5-7r4h-vj2g | DbGate has cross site scripting via the SVG Icon String Handler component |
Tue, 14 Apr 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dbgate
Dbgate dbgate |
|
| Vendors & Products |
Dbgate
Dbgate dbgate |
Tue, 14 Apr 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 13 Apr 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security vulnerability has been detected in DbGate up to 7.1.4. This affects an unknown function of the file packages/web/src/icons/FontIcon.svelte of the component SVG Icon String Handler. Such manipulation of the argument applicationIcon leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 7.1.5 mitigates this issue. It is advisable to upgrade the affected component. | |
| Title | DbGate SVG Icon String FontIcon.svelte cross site scripting | |
| Weaknesses | CWE-79 CWE-94 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-04-14T15:41:52.694Z
Reserved: 2026-04-13T13:18:23.612Z
Link: CVE-2026-6216
Updated: 2026-04-14T15:41:47.109Z
Status : Deferred
Published: 2026-04-13T21:16:32.003
Modified: 2026-04-29T01:00:01.613
Link: CVE-2026-6216
No data.
OpenCVE Enrichment
Updated: 2026-04-14T16:33:24Z
Github GHSA