Junglewise Threat Intelligence

CVE-2026-72559: HortusFox stored cross-site scripting in plant notes

CVE-2026-72559 · Severity: medium · CVSS 5.4 · Published 2026-08-11

Executive brief

HortusFox is a self-hosted collaborative plant management system used by plant enthusiasts to track and share information about plants in shared workspaces. A stored XSS vulnerability allows authenticated workspace members to inject malicious JavaScript into plant notes that executes in the browsers of all other users who view those notes, potentially enabling attackers to steal session credentials or impersonate administrators to make unauthorized changes.

Technical details

This is a stored cross-site scripting (XSS) vulnerability in HortusFox 5.9 affecting the plant notes feature. The vulnerability exists because user-supplied note content is processed by Parsedown without enabling safe mode, and the rendered output is not properly escaped before being displayed to users in the browser. An authenticated workspace member can inject persistent JavaScript code into plant notes; this payload is stored in the database and executes in the context of every user who subsequently views the affected plant, including administrators. Attackers can exploit this to steal session cookies, perform actions as other users, or escalate privileges. A patch is expected to enable safe mode in Parsedown or properly escape the rendered HTML output.

Affected products

  • Daniel Brendel HortusFox 5.9

Timeline

  • 2026-08-11: disclosed

References