VYPR

remark42

by Remark42

CVEs (2)

  • CVE-2021-29271MedMar 27, 2021
    risk 0.40cvss 6.1epss 0.01

    remark42 before 1.6.1 allows XSS, as demonstrated by "Locator: Locator{URL:" followed by an XSS payload. This is related to backend/app/store/comment.go and backend/app/store/service/service.go.

  • CVE-2026-48788Jun 16, 2026
    risk 0.00cvss epss 0.00

    Remark42 is a self-hosted comment engine for blogs, articles, or any other place where readers can add comments. Versions 1.6.0 through 1.15.0 contain a Cross-Site Scripting (XSS) vulnerability exploitable through content-type spoofing. The Remark42 image proxy fetches an…