What is CVE-2026-72743?
CVE-2026-72743 is a stored Cross-Site Scripting vulnerability in SQLBot versions up to 1.10.0, found in the SQText dashboard component that renders TinyMCE output via v-html without sanitization. Attackers who can modify dashboard text widget content can inject arbitrary HTML and JavaScript. Users should update to the version containing commit c3f40a5.
Azərbaycanca: CVE-2026-72743 SQLBot-un 1.10.0-a qədər versiyalarında SQText dashboard komponentində saxlanılan Cross-Site Scripting (XSS) zəifliyidir. TinyMCE çıxışı `v-html` vasitəsilə sanitizə edilmədən render edildiyi üçün dashboard mətn vidcetlərini dəyişə bilən hücumçular ixtiyari HTML və JavaScript kodu yeridə bilər. İstifadəçilər commit c3f40a5 ilə düzəldilmiş versiyaya yeniləmə etməlidir.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
In which component of SQLBot was CVE-2026-72743 discovered?
The vulnerability was discovered in the SQText dashboard component of SQLBot, which renders TinyMCE output via v-html without sanitization.
What should users do to protect against CVE-2026-72743?
Users should update to the version containing commit c3f40a5.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.