Users Anywhere (usersanywhere) 2.0.0 to below 2.1.0 - Authenticated Stored and Reflected XSS via Unescaped Request Input
Regular Labs Users Anywhere 2.0.0 through 2.0.6 is affected by CVE-2026-85196, fixed in 2.1.0 (released 13 September 2026). Request input consumed by Users Anywhere data tags was not escaped, and the optional raw output mode was available to any article author, allowing script to be injected into rendered content. This is the same defect and the same CVE the vendor fixed in Articles Anywhere 20.0.0, the two extensions sharing the data-tag code. Exploitation requires the ability to author or edit content containing Users Anywhere tags, or a page that already feeds request input into one. Update to 2.1.0 or later. As at 13 September 2026 the CVE record(s) for this advisory are RESERVED and not yet published, so no official CVSS score exists yet and the severity recorded here is mySites.guru's own assessment, to be revised when the records go live.
Affected versions: ≥ 2.0.0 and < 2.1.0
Full advisory: regularlabs.com