CVE-2011-5026
Winn Guestbook < 2.4.8c - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in the addPost function in data/functions.php in Winn GuestBook before 2.4.8d allows remote attackers to inject arbitrary web script or HTML via the name parameter to index.php. NOTE: some of these details are obtained from third party information.
Exploits (1)
References (5)
Scores
EPSS
0.0047
EPSS Percentile
64.1%
Classification
CWE
CWE-79
Status
published
Affected Products (10)
winn/winn_guestbook
< 2.4.8c
winn/winn_guestbook
winn/winn_guestbook
winn/winn_guestbook
winn/winn_guestbook
winn/winn_guestbook
winn/winn_guestbook
winn/winn_guestbook
winn/winn_guestbook
n/a/n/a
Timeline
Published
Dec 29, 2011
Tracked Since
Feb 18, 2026