Patch Commitpatch
https://github.com/dataease/SQLBot/commit/c3f40a5c05a53253b2924765b02b83f6a819948f CVE-2026-72743
MEDIUM
SQLBot 1.10.0 SQText Dashboard Component Stored XSS via v-html
Record summary
CVE-2026-72743 has a selected CVSS score of 5.1 (medium).
Description
SQLBot through 1.10.0, fixed in commit c3f40a5, contains a stored cross-site scripting vulnerability in the SQText dashboard component that renders TinyMCE output via v-html without sanitization. Attackers who can modify dashboard text widget content can inject arbitrary HTML and JavaScript that executes for all users viewing the dashboard.
Description source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
SQLBotBrowse dataease / SQLBotDefault status: affected | CVE List | Through 1.10.0 | affected |
| c3f40a5c05a53253b2924765b02b83f6a819948f | unaffected |
References
5Researcher DisclosureTechnical descriptionexploit
https://github.com/dataease/SQLBot/issues/1308 Pull Requestissue tracking
https://github.com/dataease/SQLBot/pull/1309 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-72743 vulncheck.comThird-party advisory
https://www.vulncheck.com/advisories/sqlbot-sqtext-dashboard-component-stored-xss-via-v-html