Skip to content
Saturday, August 22, 2026
KAJ NEWSCYBER · PRIVACY · SECURITY

CVE-2026-53529

The CVE Severity Digest turns the National Vulnerability Database feed into a prioritized security briefing. It groups affected software into practical product families, distinguishes patch and mitigation references from general citations, and ranks the vulnerabilities most likely to matter to technology operators while preserving direct links to the official record.

Records
199
Last changed
Update schedule
17 6 * * * UTC
Coverage
08/15/2026–08/22/2026
Method
Methodology
CVE
CVE-2026-53529
Description
LeafWiki is a self-hosted wiki. Prior to version 0.10.2, page titles returned by the search API could be rendered as raw HTML in the frontend. A user with editor or administrator permissions could create or modify a page title containing an HTML/JavaScript payload. When another user searched for a matching term, the payload could execute in the victim’s browser. The impact depends on deployment configuration. With `--public-access` enabled, unauthenticated visitors could be affected. In authenticated-only deployments, the issue could be used for cross-user XSS against logged-in users who can access search results. The issue has been fixed in version 0.10.2 by ensuring that author-controlled page titles in search results are not interpreted as raw HTML by the browser while preserving search result highlighting.
Published
08/21/2026
Severity
MEDIUM
CVSS
4.8
Priority score
49.352