Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade Heptabase to version 1.93.1 or later
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 24 Aug 2026 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hepta Platforms
Hepta Platforms heptabase |
|
| Vendors & Products |
Hepta Platforms
Hepta Platforms heptabase |
Mon, 24 Aug 2026 04:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Heptabase developed by Hepta Platforms, Inc. has a Stored Cross-Site Scripting vulnerability. Authenticated remote attackers can inject persistent malicious content into specific pages, causing arbitrary JavaScript code to execute when other users click the crafted content. | |
| Title | Hepta Platforms|Heptabase - Stored Cross-Site Scripting | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2026-08-24T03:53:47.403Z
Reserved: 2026-08-24T02:03:00.828Z
Link: CVE-2026-78213
No data.
Status : Received
Published: 2026-08-24T04:16:59.817
Modified: 2026-08-24T04:16:59.817
Link: CVE-2026-78213
No data.
OpenCVE Enrichment
Updated: 2026-08-24T05:30:12Z
-
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')