CVE-2026-78213: Hepta Platforms Heptabase
High severity, CVSS 8.7. EPSS: 0.4% chance of exploitation in the next 30 days.
Heptabase developed by Hepta Platforms, Inc. has a Stored Cross-Site Scripting vulnerability. Authenticated remote attackers can inject persistent malicious content into specific pages, causing arbitrary JavaScript code to execute when other users click the crafted content.
Affected products
- Hepta Platforms Heptabase: any version
Published 2026-08-24. Last modified 2026-08-26.