CVE-2011-1158
Mark Pilgrim Feedparser < 5.0.1 - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in feedparser.py in Universal Feed Parser (aka feedparser or python-feedparser) 5.x before 5.0.1 allows remote attackers to inject arbitrary web script or HTML via an unexpected URI scheme, as demonstrated by a javascript: URI.
References (11)
Scores
EPSS
0.0062
EPSS Percentile
69.7%
Classification
CWE
CWE-79
Status
published
Affected Products (3)
mark_pilgrim/feedparser
pypi/feedparser
< 5.0.1PyPI
n/a/n/a
Timeline
Published
Apr 11, 2011
Tracked Since
Feb 18, 2026