All 3 CVE vulnerabilities found in shiori, with AI-generated Chinese analysis, references, and POCs.
Vendor: go-shiori
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-71280 | go-shiori Server-Side Request Forgery via Unrestricted Bookmark URL Fetch CWE-918 | 8.5 | High | 2026-08-05 |
| CVE-2026-71206 | shiori: JWT CheckToken Never Re-Validates Account State, Allowing Stale-Privilege Access After Deletion or Demotion CWE-613 | 8.2 | High | 2026-08-05 |
| CVE-2026-61463 | Shiori Authenticated Privilege Escalation via PATCH /api/v1/auth/account CWE-269 | 8.8 | High | 2026-07-13 |
All 3 known CVE vulnerabilities affecting shiori with full Chinese analysis, references, and POCs where available.