以下是对该漏洞描述信息的中文翻译: AIL 框架中的标签选择器组件(位于 )存在存储型跨站脚本(Stored XSS)漏洞。拥有创建自定义标签权限的用户可以在标签名称中嵌入包含 JavaScript 事件处理器的 HTML 载荷(例如 或 )。当其他已认证用户打开包含该标签选择器的页面时,恶意标签名称会通过 jQuery 的 属性被插入到 DOM 中,导致嵌入的脚本在受害者浏览器的上下文中执行。 受影响的脆弱代码路径包括建议/组合项渲染( )以及已选标签的渲染逻辑。在这两种情况下,源自标签 的显示值被直接传递给 j
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| ail project | ail framework | < 7.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ail project | ail framework | 0 ~ 7.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100172 | 8.5 HIGH | Stored XSS in AIL Framework extracted-match popovers via unescaped dynamic values in HTML- |
| CVE-2026-100176 | 8.5 HIGH | Stored Cross-Site Scripting (XSS) in AIL Framework Username Timeline Tooltip |
| CVE-2026-100187 | 6.9 MEDIUM | AIL Framework Onion Module: Non-Onion URL Accepted as Crawler Task Due to Bypassed Domain |
| CVE-2026-100177 | 6.3 MEDIUM | Ail Framework Crawler: Missing Cookiejar Authorization Check Allows Cross-Organization Coo |
| CVE-2026-100190 | 6.3 MEDIUM | Stored Cross-Site Scripting (XSS) via Crawler Capture Import in AIL Framework showDomain P |
No comments yet