CVE-2014-3995

Djblets < 0.7.30 - Cross-Site Scripting via User Display Name

Title source: llm
STIX 2.1

Description

Cross-site scripting (XSS) vulnerability in gravatars/templatetags/gravatars.py in Djblets before 0.7.30 and 0.8.x before 0.8.3 for Django allows remote attackers to inject arbitrary web script or HTML via a user display name.

References (6)

Core 6

Scores

EPSS 0.0208
EPSS Percentile 79.2%

Details

CWE
CWE-79
Status published
Products (6)
pypi/Djblets 0 - 0.7.30PyPI
reviewboard/djblets 0.7.27
reviewboard/djblets 0.7.28
reviewboard/djblets 0.8.1
reviewboard/djblets 0.8.2
reviewboard/djblets < 0.7.29
Published Jun 16, 2014
Tracked Since Feb 18, 2026