Medium severity4.4NVD Advisory· Published Aug 20, 2026
CVE-2026-77643
CVE-2026-77643
Description
A cross-site scripting vulnerability in queryparser/termgenerator_internal.cc in Xapian xapian-core before 2.1.0 and before 1.4.32 exists due to incomplete HTML escaping by Xapian::MSet::snippet(). NOTE: this issue exists because of a missed corner case of CVE-2018-0499.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <2.1.0, <1.4.32
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.