Unrated severityNVD Advisory· Published Jan 15, 2026· Updated Mar 5, 2026
Tagstoo 2.0.1 - Stored XSS to RCE
CVE-2021-47843
Description
Tagstoo 2.0.1 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious payloads through files or custom tags. Attackers can execute arbitrary JavaScript code to spawn system processes, access files, and perform remote code execution on the victim's computer.
Affected products
2- Tagstoo/Tagstoov5Range: 2.0.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.exploit-db.com/exploits/49828mitreexploit
- imgur.com/a/smeAjaWmitreproduct
- tagstoo.sourceforge.iomitreproduct
News mentions
0No linked articles in our index yet.