olivier-ls PHP-FTS XSS via buildHighlights up to 1.1.2 (fixed 1.1.3)
CVE-2026-93956 Published on September 19, 2026

olivier-ls PHP-FTS Search SearchEngine.php buildHighlights cross site scripting
A flaw has been found in olivier-ls PHP-FTS up to 1.1.2. Affected by this issue is the function SearchEngine::buildHighlights of the file src/SearchEngine.php of the component Search Engine. Executing a manipulation of the argument Query can lead to cross site scripting. The attack may be launched remotely. The exploit has been published and may be used. Upgrading to version 1.1.3 can resolve this issue. This patch is called 0b2fae333d6b022da7ed4c43e2d41aa03f91dff3. The affected component should be upgraded. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

NVD

Timeline

Advisory disclosed

VulDB entry created

VulDB entry last update

Weakness Types

What is a XSS Vulnerability?

The software does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

CVE-2026-93956 has been classified to as a XSS vulnerability or weakness.

What is a Code Injection Vulnerability?

The software constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

CVE-2026-93956 has been classified to as a Code Injection vulnerability or weakness.


Products Associated with CVE-2026-93956

Want to know whenever a new CVE is published for Olivier Ls Php Fts? stack.watch will email you.

 

Affected Versions

olivier-ls PHP-FTS: