queryparser/termgenerator_internal.cc in Xapian xapian-core before 2.1.0 and before 1.4.32 exists due to incomplete HTML escaping by Xapian::MSet::snippet(). NOTE: this issue exists because of a missed corner case of CVE-2018-0499.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 20 Aug 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A cross-site scripting vulnerability in queryparser/termgenerator_internal.cc in Xapian xapian-core before 2.1.0 and before 1.4.32 exists due to incomplete HTML escaping by Xapian::MSet::snippet(). NOTE: this issue exists because of a missed corner case of CVE-2018-0499. | |
| First Time appeared |
Xapian
Xapian xapian-core |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:xapian:xapian-core:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Xapian
Xapian xapian-core |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-08-20T21:23:31.317Z
Reserved: 2026-08-20T21:23:30.985Z
Link: CVE-2026-77643
No data.
Status : Received
Published: 2026-08-20T22:18:06.207
Modified: 2026-08-20T22:18:06.207
Link: CVE-2026-77643
No data.
OpenCVE Enrichment
No data.
-
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')