CVE-2025-62528

MEDIUM5.4EPSS 0.02%

Taguette vulnerable to cross-site scripting via tag name, tag description, document name and document description

Published: 10/20/2025Modified: 5/20/2026

Description

Taguette is an open source qualitative research tool. An issue has been discovered in Taguette versions prior to 1.5.0. It was possible for a project member to put JavaScript in name or description fields which would run on project load. This issue has been patched in version 1.5.0.

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM5.4CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

References (4)