CVE-2011-4312

Review Board <1.5.7, <1.6.3 - XSS

Title source: llm

Description

Multiple cross-site scripting (XSS) vulnerabilities in the commenting system in Review Board before 1.5.7 and 1.6.x before 1.6.3 allow remote attackers to inject arbitrary web script or HTML via vectors involving the (1) diff viewer or (2) screenshot component.

Scores

EPSS 0.0056
EPSS Percentile 67.9%

Classification

CWE
CWE-79
Status published

Affected Products (41)

reviewboard/review_board < 1.5.6
reviewboard/review_board
reviewboard/review_board
reviewboard/review_board
reviewboard/review_board
reviewboard/review_board
reviewboard/review_board
reviewboard/review_board
reviewboard/review_board
reviewboard/review_board
reviewboard/review_board
reviewboard/review_board
reviewboard/review_board
reviewboard/review_board
reviewboard/review_board
... and 26 more

Timeline

Published Nov 24, 2011
Tracked Since Feb 18, 2026