CVE-2026-60119

Source
https://cve.org/CVERecord?id=CVE-2026-60119
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-60119.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-60119
Aliases
  • GHSA-2ggx-79g6-2jmj
Published
2026-07-14T15:44:34Z
Modified
2026-08-12T03:51:14Z
Severity
  • 5.1 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N CVSS Calculator
Summary
Hi.Events < 1.11.0 XSS via Event Title JSON.stringify Injection
Details

Hi.Events before 1.11.0 contains a cross-site scripting vulnerability that allows authenticated attackers with event creation or edit permissions to inject arbitrary HTML and JavaScript by embedding a malicious event title containing the sequence, which is not escaped by JSON.stringify() when embedded in inline script tags. Attackers can craft an event title that breaks out of the script context in the application/ld+json structured data block or server-side rehydrated state, causing the payload to execute in the browser of any user who views the public event page, including unauthenticated visitors and authenticated administrators.

Database specific
{
    "cna_assigner":  "VulnCheck",
    "cwe_ids":  [
        "CWE-862"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/60xxx/CVE-2026-60119.json",
    "unresolved_ranges":  [
        {
            "extracted_events":  [
                {
                    "fixed":  "1.11.0"
                }
            ],
            "source":  "AFFECTED_FIELD"
        },
        {
            "extracted_events":  [
                {
                    "fixed":  "1.11.0"
                }
            ],
            "source":  "CPE_FIELD"
        },
        {
            "extracted_events":  [
                {
                    "introduced":  "Hi.Events"
                },
                {
                    "fixed":  "1.11.0"
                }
            ],
            "source":  "DESCRIPTION"
        }
    ]
}
References

Affected packages

Git / github.com/hieventsdev/hi.events

Affected ranges

Type
GIT
Repo
https://github.com/hieventsdev/hi.events
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "source":  "REFERENCES"
}

Affected versions

v.*
v.1.10.0-beta
v0.*
v0.1.0-alpha.1
v0.1.0-alpha.10
v0.1.0-alpha.11
v0.1.0-alpha.12
v0.1.0-alpha.13
v0.1.0-alpha.14
v0.1.0-alpha.15
v0.1.0-alpha.16
v0.1.0-alpha.17
v0.1.0-alpha.2
v0.1.0-alpha.3
v0.1.0-alpha.4
v0.1.0-alpha.5
v0.1.0-alpha.6
v0.1.0-alpha.8
v0.1.0-alpha.9
v0.2.0-alpha.1
v0.2.0-alpha.2
v0.2.0-alpha.3
v0.3.0-alpha.1
v0.3.0-alpha.2
v0.3.0-alpha.3
v0.4.0-alpha.1
v0.4.0-alpha.2
v0.5.0-alpha.1
v0.5.0-alpha.2
v0.6.0-alpha.1
v0.6.0-alpha.2
v0.6.0-alpha.3
v0.7.0-alpha.1
v0.7.0-alpha.2
v0.7.0-alpha.3
v0.7.0-beta.1
v0.7.0-beta.2
v0.7.0-beta.3
v0.7.0-beta.4
v0.7.0-beta.5
v0.7.0-beta.6
v0.8.0-beta.1
v0.8.0-beta.2
v0.8.0-beta.3
v0.8.0-beta.4
v0.8.0-beta.5
v0.8.0-beta.6
v0.8.0-beta.7
v0.8.0-beta.8
v0.8.0-beta.9
v1.*
v1.0.0-alpha.10
v1.0.0-alpha.11
v1.0.0-alpha.12
v1.0.0-alpha.13
v1.0.0-alpha.14
v1.0.0-alpha.15
v1.0.0-alpha.16
v1.0.0-alpha.17
v1.0.0-alpha.5
v1.0.0-alpha.6
v1.0.0-alpha.7
v1.0.0-alpha.8
v1.0.0-alpha.9
v1.0.0-beta.1
v1.0.0-beta.2
v1.0.0-beta.3
v1.0.0-beta.4
v1.0.0-beta.5
v1.0.0-beta.6
v1.1.0-alpha.1
v1.1.0-alpha.2
v1.1.0-beta.1
v1.1.0-beta.2
v1.2.0-beta.1
v1.3.0-beta.1
v1.4.0-beta.1
v1.5.0-beta.1
v1.5.1-beta.1
v1.6.0-beta.1
v1.7.0-beta
v1.7.1-beta
v1.8.0-beta
v1.9.0-beta

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-60119.json"