CVE-2011-5267
Wikiwig - XSS
Title source: ruleDescription
Multiple cross-site scripting (XSS) vulnerabilities in spell-check-savedicts.php in the SpellChecker module in Xinha, as used in WikiWig 5.01 and possibly other products, allow remote attackers to inject arbitrary web script or HTML via the (1) to_p_dict or (2) to_r_list parameter. NOTE: this issue might be related to the htmlarea plugin and CVE-2013-5670.
Exploits (2)
exploitdb
WRITEUP
VERIFIED
by John Leitch · textwebappsphp
https://www.exploit-db.com/exploits/35436
References (5)
Scores
EPSS
0.0993
EPSS Percentile
92.9%
Classification
CWE
CWE-79
Status
draft
Affected Products (1)
wikiwig_project/wikiwig
Timeline
Published
Nov 05, 2013
Tracked Since
Feb 18, 2026