Tagstoo 2.0.1 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious payloads through files or custom tags. Attackers can execute arbitrary JavaScript code to spawn system processes, access files, and perform remote code execution on the victim's computer.
History

Fri, 16 Jan 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Tagstoo
Tagstoo tagstoo
Vendors & Products Tagstoo
Tagstoo tagstoo

Thu, 15 Jan 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 15 Jan 2026 16:00:00 +0000

Type Values Removed Values Added
Description Tagstoo 2.0.1 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious payloads through files or custom tags. Attackers can execute arbitrary JavaScript code to spawn system processes, access files, and perform remote code execution on the victim's computer.
Title Tagstoo 2.0.1 - Stored XSS to RCE
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-01-15T16:08:43.026Z

Reserved: 2026-01-14T17:11:19.902Z

Link: CVE-2021-47843

cve-icon Vulnrichment

Updated: 2026-01-15T16:08:40.483Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-01-15T16:16:10.537

Modified: 2026-01-16T15:55:33.063

Link: CVE-2021-47843

cve-icon Redhat

No data.