CVE-2011-1401
ikiwiki <3.20110328 - XSS
Title source: llmDescription
ikiwiki before 3.20110328 does not ascertain whether the htmlscrubber plugin is enabled during processing of the "meta stylesheet" directive, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks via crafted Cascading Style Sheets (CSS) token sequences in (1) the default stylesheet or (2) an alternate stylesheet.
References (8)
Scores
EPSS
0.0039
EPSS Percentile
59.4%
Classification
CWE
CWE-79
Status
published
Affected Products (50)
ikiwiki/ikiwiki
< 3.20110321
ikiwiki/ikiwiki
ikiwiki/ikiwiki
ikiwiki/ikiwiki
ikiwiki/ikiwiki
ikiwiki/ikiwiki
ikiwiki/ikiwiki
ikiwiki/ikiwiki
ikiwiki/ikiwiki
ikiwiki/ikiwiki
ikiwiki/ikiwiki
ikiwiki/ikiwiki
ikiwiki/ikiwiki
ikiwiki/ikiwiki
ikiwiki/ikiwiki
... and 35 more
Timeline
Published
Apr 11, 2011
Tracked Since
Feb 18, 2026