CVE-2021-25986
Dashboard / Vulnerabilities / CVE-2021-25986
CVE-2021-25986
Published: 23 Nov 2021Last Modified: 9 Jul 2026
Aliases:
Summary:
Details: In Django-wiki, versions 0.0.20 to 0.7.8 are vulnerable to Stored Cross-Site Scripting (XSS) in Notifications Section. An attacker who has access to edit pages can inject JavaScript payload in the title field. When a victim gets a notification regarding the changes made in the application, the payload in the notification panel renders and loads external JavaScript.
References: https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25986, https://github.com/django-wiki/django-wiki/commit/9eaccc7519e4206a4d2f22640882f0737b2da9c5
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
Introduced- 00cf45b6dc5c82efab2fbf79ad1560bc722509f1
Fixed -None
Affected versions
releases/0.7.8
releases/0.7.7
releases/0.7.6
releases/0.7.5
releases/0.7.4
releases/0.7.3
releases/0.7.2
releases/0.7.1
releases/0.7
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
