Tagstoo 2.0.1 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious payloads through files or custom tags. Attackers can execute arbitrary JavaScript code to spawn system processes, access files, and perform remote code execution on the victim's computer.

Project Subscriptions

Vendors Products
Pabloandumundu Subscribe
Tagstoo Subscribe
Tagstoo Subscribe
Tagstoo Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 05 Feb 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Pabloandumundu
Pabloandumundu tagstoo
CPEs cpe:2.3:a:tagstoo:tagstoo:2.0.1:*:*:*:*:*:*:* cpe:2.3:a:pabloandumundu:tagstoo:2.0.1:*:*:*:*:*:*:*
Vendors & Products Pabloandumundu
Pabloandumundu tagstoo

Mon, 02 Feb 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'}

cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Thu, 29 Jan 2026 19:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:tagstoo:tagstoo:2.0.1:*:*:*:*:*:*:*

Fri, 16 Jan 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Tagstoo
Tagstoo tagstoo
Vendors & Products Tagstoo
Tagstoo tagstoo

Thu, 15 Jan 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 15 Jan 2026 16:00:00 +0000

Type Values Removed Values Added
Description Tagstoo 2.0.1 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious payloads through files or custom tags. Attackers can execute arbitrary JavaScript code to spawn system processes, access files, and perform remote code execution on the victim's computer.
Title Tagstoo 2.0.1 - Stored XSS to RCE
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-02-02T15:58:17.466Z

Reserved: 2026-01-14T17:11:19.902Z

Link: CVE-2021-47843

cve-icon Vulnrichment

Updated: 2026-01-15T16:08:40.483Z

cve-icon NVD

Status : Analyzed

Published: 2026-01-15T16:16:10.537

Modified: 2026-02-05T19:20:08.023

Link: CVE-2021-47843

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-01-16T13:43:29Z

Weaknesses