CVE WATCH / VULNERABILITY DETAIL

CVE-2026-18311

MEDIUMCVSS 6.1NVD feed

Published 25 September 2026 · tracked since 26 September 2026

Description

Readwise Reader for Android contains a cross-site scripting vulnerability due to missing HTML sanitization in its processing of imported document metadata. Attacker-controlled fields such as the author meta tag are inserted into a WebView via innerHTML, enabling stored XSS that executes on synced de

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-18311 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-18311

MEDIUMCVSS 6.1NVD feed

Published 25 September 2026 · tracked since 26 September 2026

Description

Readwise Reader for Android contains a cross-site scripting vulnerability due to missing HTML sanitization in its processing of imported document metadata. Attacker-controlled fields such as the author meta tag are inserted into a WebView via innerHTML, enabling stored XSS that executes on synced de

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]