What is CVE-2026-72559?
CVE-2026-72559 is a stored cross-site scripting vulnerability in HortusFox version 5.9, where authenticated workspace members can inject persistent JavaScript into plant notes due to Parsedown being rendered without safe mode. This vulnerability exposes all users viewing the affected plant to script execution in their browsers. Affected users should immediately apply the security patch provided by the HortusFox developer or enable safe mode in Parsedown to mitigate the risk.
Azərbaycanca: CVE-2026-72559, HortusFox 5.9 versiyasında autentifikasiya olunmuş istifadəçilərin Parsedown renderləyicisinin təhlükəsizlik rejimi aktiv olmadığı üçün bitki qeydlərinə saxlanılan XSS hücumu həyata keçirməsinə imkan verir. Bu zəiflik iş sahəsi üzvlərinə zərərli JavaScript kodunu qeydlərə əlavə edərək, həmin bitkiyə baxan bütün istifadəçilərin brauzerində kodun icrasına səbəb olur. Təsirə məruz qalmamaq üçün istifadəçilər dərhal HortusFox tərtibatçısının təqdim etdiyi təhlükəsizlik yeniləməsini tətbiq etməli və ya Parsedown renderləyicisində safe mode funksiyasını aktivləşdirməlidirlər.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which version of HortusFox is affected by CVE-2026-72559?
CVE-2026-72559 affects HortusFox version 5.9.
What is the root cause of CVE-2026-72559?
The vulnerability occurs because the Parsedown renderer is used without safe mode enabled.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.