CVE-2011-1838
TWiki <5.0.2 - XSS
Title source: llmDescription
Multiple cross-site scripting (XSS) vulnerabilities in TemplateLogin.pm in TWiki before 5.0.2 allow remote attackers to inject arbitrary web script or HTML via the origurl parameter to a (1) view script or (2) login script.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Mesut Timur · textwebappsphp
https://www.exploit-db.com/exploits/35761
References (8)
Scores
EPSS
0.0904
EPSS Percentile
92.5%
Classification
CWE
CWE-79
Status
published
Affected Products (21)
twiki/twiki
< 5.0.1
twiki/twiki
twiki/twiki
twiki/twiki
twiki/twiki
twiki/twiki
twiki/twiki
twiki/twiki
twiki/twiki
twiki/twiki
twiki/twiki
twiki/twiki
twiki/twiki
twiki/twiki
twiki/twiki
... and 6 more
Timeline
Published
May 20, 2011
Tracked Since
Feb 18, 2026