HIGH
dhis2
CVE published 2026-07-21
CVE-2026-55081
The DHIS2 OpenAPI HTML endpoint reflected values from the `scope` query parameter into the generated HTML document without sufficient sanitization, allowing a crafted `scope` value to be rendered as active HTML or JavaScript. This vulnerability affects DHIS2 versions 2.42 and 2.43 before the 2026-06-09 security patch releases, and the development branch for DHIS2 2.44 before the fix was merged. Users of t [truncated]