PatchSiren

Xapian CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Xapian CVE published 2026-08-20

CVE-2026-77643

A cross-site scripting vulnerability exists in Xapian xapian-core before 2.1.0 and before 1.4.32 due to incomplete HTML escaping by Xapian::MSet::snippet(). This vulnerability allows attackers to inject malicious scripts into web pages, potentially leading to unauthorized actions or data breaches. Defenders should assess the vulnerability's impact on their systems and prioritize patching to prevent potent [truncated]