CVE-2026-78213: Hepta Platforms Heptabase

High severity, CVSS 8.7. EPSS: 0.4% chance of exploitation in the next 30 days.

Heptabase developed by Hepta Platforms, Inc. has a Stored Cross-Site Scripting vulnerability. Authenticated remote attackers can inject persistent malicious content into specific pages, causing arbitrary JavaScript code to execute when other users click the crafted content.

Affected products

Published 2026-08-24. Last modified 2026-08-26.