SHIRASAGI vulnerabilities
CVEs whose affected-version data names the SHIRASAGI package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-81635Medium· 5.4A cross-site scripting vulnerability exists in SHIRASAGI, which may allow an attacker to execute an arbitrary script in the web browser of a user who accesses a website using the affected product.
A cross-site scripting vulnerability exists in SHIRASAGI, which may allow an attacker to execute an arbitrary script in the web browser of a user who accesses a website using the affected product.
▾ SunlitSHIRASAGI Project · SHIRASAGIEPSS 0.15%via NVD
CVE-2026-82582Medium· 4.3An authorization bypass vulnerability exists in SHIRASAGI through a user-controlled key, which may allow an unauthorized attacker to retrieve files from the groupware's shared file feature.
An authorization bypass vulnerability exists in SHIRASAGI through a user-controlled key, which may allow an unauthorized attacker to retrieve files from the groupware's shared file feature.
▾ SunlitSHIRASAGI Project · SHIRASAGIEPSS 0.20%via NVD