CVE-2026-105263
Last modified
CVE-2026-105263 is a medium-severity vulnerability rated 4.7/10 on the CVSS scale. A security flaw has been discovered in Shaarli up to 0.16.3. The affected element is the function MetadataController of the file application/front/controller/admin/MetadataController.php of the component Admin Metadata Endpoint.
Description
A security flaw has been discovered in Shaarli up to 0.16.3. The affected element is the function MetadataController of the file application/front/controller/admin/MetadataController.php of the component Admin Metadata Endpoint. Performing a manipulation of the argument url results in server-side request forgery. The attack may be initiated remotely. Upgrading to version 0.16.4 is sufficient to fix this issue. The patch is named 8ca4de8e7c932a684481f5fbb1229fe16de1f4d2. It is advisable to upgrade the affected component.
Metrics
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-105263?
How severe is CVE-2026-105263?
How do I fix CVE-2026-105263?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-10525The NEX-Forms WordPress plugin before 9.2.3 does not saniti…6.1
- CVE-2026-105250A security vulnerability has been detected in vgmstream up t…4.3
- CVE-2026-105251A vulnerability was detected in vgmstream up to r2117. Affec…6.3
- CVE-2026-105253A vulnerability was determined in itsourcecode Online Admiss…7.3
- CVE-2026-105254A vulnerability was identified in itsourcecode Online Admiss…6.3
- CVE-2026-10526The EmbedPress WordPress plugin before 4.6.1 does not valid…5.8
- CVE-2026-10527Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 1…6.3
- CVE-2026-10528A security flaw has been discovered in Orthanc DICOM Server …3.3
- CVE-2026-105284A weakness has been identified in Totolink A3002MU 1.0.0-B20…10
- CVE-2026-105285A security vulnerability has been detected in Totolink A3002…10
- CVE-2026-105286A vulnerability was detected in Totolink A3002MU 1.0.0-B2023…6.3
- CVE-2026-105287A flaw has been found in feelec-yishu feelcrm-os 1.0.0. Affe…6.3
Are you affected by CVE-2026-105263?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
