Description
@diplodoc/search-extension 1.0.0 through 3.0.2 allows stored XSS via .md file title.
Recommendation
Update the @diplodoc/search-extension package to the latest compatible version. Followings are version details:
- Affected version(s): >= 1.0.0, < 3.0.5
- Patched version(s): 3.0.5
References
Could your website be exposed too?
SmartScanner can check your website for @diplodoc/search-extension allows stored XSS via Markdown file title and gives you actionable findings to investigate.
Start a free scanRelated Issues
- HAX CMS: Stored XSS via '<video-player>' component allows arbitrary JavaScript execution and token theft - CVE-2026-46496
- Stored XSS via <iframe> in HAX CMS allows access to sensitive client-side data and account takeover - CVE-2026-46396
- Stored XSS via <iframe> in HAX CMS allows access to sensitive client-side data and account takeover - @haxtheweb/video-player - CVE-2026-46396
- Open WebUI has Stored XSS in Banner Component via Improper Sanitization Order - CVE-2026-45665
You might also like:
See something that needs correcting? Let us knowUpdated May 07, 2026


