Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 02 Sep 2026 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | NocoBase fails to sanitize rich text field values in the read renderer, allowing users with create permissions to store malicious HTML with event handlers. Attackers can write arbitrary markup through the collection API that executes in the browsers of all users viewing the affected record. | |
| Title | NocoBase Rich Text Field Stored Cross-Site Scripting via API | |
| First Time appeared |
Nocobase
Nocobase nocobase |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:nocobase:nocobase:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Nocobase
Nocobase nocobase |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-02T00:37:55.776Z
Reserved: 2026-09-01T23:24:29.734Z
Link: CVE-2026-84701
No data.
Status : Received
Published: 2026-09-02T01:17:25.287
Modified: 2026-09-02T01:17:25.287
Link: CVE-2026-84701
No data.
OpenCVE Enrichment
Updated: 2026-09-02T04:30:04Z