MEDIUM
CVE-2026-91021
CVSS
5.4
Description
Trilium Notes, version v0.103.0 and earlier, contains a stored cross-site scripting (XSS) vulnerability in the share renderer for webView notes due to improper HTML escaping of user-controlled #webViewSrc values. This vulnerability allows attackers with note-authoring privileges to inject arbitrary JavaScript that executes for any user who opens the shared note, including administrators.
Weakness (CWE)
CWE-79
Cross-site Scripting (XSS)
EPSS Score
0.14%
Probability of exploitation in next 30 days
3.8th percentile
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.