PT-2026-54899 · Unknown · Syntaxhighlight Geshi
CVE-2026-58030
·
Published
2026-07-01
·
Updated
2026-07-01
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
SyntaxHighlight GeSHi versions prior to 1.46.0
SyntaxHighlight GeSHi version 1.45.4
SyntaxHighlight GeSHi version 1.44.6
SyntaxHighlight GeSHi version 1.43.9
Description
Improper neutralization of input during web page generation leads to a stored Cross-site Scripting (XSS) issue in the
includes/SyntaxHighlight.Php file. This occurs via the unsanitized linelinks attribute.Recommendations
Update SyntaxHighlight GeSHi to version 1.46.0 or later.
Update SyntaxHighlight GeSHi to a version newer than 1.45.4.
Update SyntaxHighlight GeSHi to a version newer than 1.44.6.
Update SyntaxHighlight GeSHi to a version newer than 1.43.9.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Syntaxhighlight Geshi