CVE-2011-1401

low
Published 2011-04-11 ยท Modified 2026-04-29
CVSS v3
โ€”
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
3.5

Description

ikiwiki before 3.20110328 does not ascertain whether the htmlscrubber plugin is enabled during processing of the "meta stylesheet" directive, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks via crafted Cascading Style Sheets (CSS) token sequences in (1) the default stylesheet or (2) an alternate stylesheet.

Predictions

Exploit likelihood
20%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No mitigations published for this CVE yet.

The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ€” if you've already worked around this in production โ€” publish your fix to the community-verified tier.

โœš Propose a mitigation on Community โ†’ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here with source_tier=community-verified.

OS impact

debian Debian Fixed 5 releases
VersionStatusFixed in
trixie Fixed 3.20110328
sid Fixed 3.20110328
forky Fixed 3.20110328
bullseye Fixed 3.20110328
bookworm Fixed 3.20110328

Application impact

VendorProductVersionsFixed
ikiwikiikiwiki{"endIncluding":"3.20110321"}
ikiwikiikiwiki1.0
ikiwikiikiwiki1.1
ikiwikiikiwiki1.1.47
ikiwikiikiwiki1.2
ikiwikiikiwiki1.3
ikiwikiikiwiki1.4
ikiwikiikiwiki1.5
ikiwikiikiwiki1.6
ikiwikiikiwiki1.7
ikiwikiikiwiki1.8
ikiwikiikiwiki1.9
ikiwikiikiwiki1.10
ikiwikiikiwiki1.11
ikiwikiikiwiki1.12
ikiwikiikiwiki1.13
ikiwikiikiwiki1.14
ikiwikiikiwiki1.15
ikiwikiikiwiki1.16
ikiwikiikiwiki1.17
ikiwikiikiwiki1.18
ikiwikiikiwiki1.19
ikiwikiikiwiki1.20
ikiwikiikiwiki1.21
ikiwikiikiwiki1.22
ikiwikiikiwiki1.23
ikiwikiikiwiki1.24
ikiwikiikiwiki1.25
ikiwikiikiwiki1.26
ikiwikiikiwiki1.27
ikiwikiikiwiki1.28
ikiwikiikiwiki1.29
ikiwikiikiwiki1.30
ikiwikiikiwiki1.31
ikiwikiikiwiki1.32
ikiwikiikiwiki1.33.3
ikiwikiikiwiki1.34
ikiwikiikiwiki1.34.1
ikiwikiikiwiki1.34.2
ikiwikiikiwiki1.35
ikiwikiikiwiki1.36
ikiwikiikiwiki1.37
ikiwikiikiwiki1.38
ikiwikiikiwiki1.39
ikiwikiikiwiki1.40
ikiwikiikiwiki1.41
ikiwikiikiwiki1.42
ikiwikiikiwiki1.43
ikiwikiikiwiki1.44
ikiwikiikiwiki1.45
ikiwikiikiwiki1.46
ikiwikiikiwiki1.47
ikiwikiikiwiki1.48
ikiwikiikiwiki1.49
ikiwikiikiwiki1.50
ikiwikiikiwiki1.51
ikiwikiikiwiki2.0
ikiwikiikiwiki2.00
ikiwikiikiwiki2.1
ikiwikiikiwiki2.2
ikiwikiikiwiki2.3
ikiwikiikiwiki2.4
ikiwikiikiwiki2.5
ikiwikiikiwiki2.6
ikiwikiikiwiki2.6.1
ikiwikiikiwiki2.7
ikiwikiikiwiki2.8
ikiwikiikiwiki2.9
ikiwikiikiwiki2.10
ikiwikiikiwiki2.11
ikiwikiikiwiki2.12
ikiwikiikiwiki2.13
ikiwikiikiwiki2.14
ikiwikiikiwiki2.15
ikiwikiikiwiki2.16
ikiwikiikiwiki2.17
ikiwikiikiwiki2.18
ikiwikiikiwiki2.19
ikiwikiikiwiki2.20
ikiwikiikiwiki2.30
ikiwikiikiwiki2.31
ikiwikiikiwiki2.31.1
ikiwikiikiwiki2.31.2
ikiwikiikiwiki2.31.3
ikiwikiikiwiki2.40
ikiwikiikiwiki2.41
ikiwikiikiwiki2.42
ikiwikiikiwiki2.43
ikiwikiikiwiki2.44
ikiwikiikiwiki2.45
ikiwikiikiwiki2.46
ikiwikiikiwiki2.47
ikiwikiikiwiki2.48
ikiwikiikiwiki2.49
ikiwikiikiwiki2.50
ikiwikiikiwiki2.51
ikiwikiikiwiki2.52
ikiwikiikiwiki2.53
ikiwikiikiwiki2.54
ikiwikiikiwiki2.55
ikiwikiikiwiki2.56
ikiwikiikiwiki2.60
ikiwikiikiwiki2.61
ikiwikiikiwiki2.62
ikiwikiikiwiki2.62.1
ikiwikiikiwiki2.63
ikiwikiikiwiki2.64
ikiwikiikiwiki2.65
ikiwikiikiwiki2.66
ikiwikiikiwiki2.67
ikiwikiikiwiki2.68
ikiwikiikiwiki2.69
ikiwikiikiwiki2.70
ikiwikiikiwiki2.71
ikiwikiikiwiki2.72
ikiwikiikiwiki3.0
ikiwikiikiwiki3.00
ikiwikiikiwiki3.01
ikiwikiikiwiki3.02
ikiwikiikiwiki3.03
ikiwikiikiwiki3.04
ikiwikiikiwiki3.05
ikiwikiikiwiki3.06
ikiwikiikiwiki3.07
ikiwikiikiwiki3.08
ikiwikiikiwiki3.09
ikiwikiikiwiki3.10
ikiwikiikiwiki3.11
ikiwikiikiwiki3.12
ikiwikiikiwiki3.13
ikiwikiikiwiki3.14
ikiwikiikiwiki3.141
ikiwikiikiwiki3.1415
ikiwikiikiwiki3.14159
ikiwikiikiwiki3.141592
ikiwikiikiwiki3.1415926
ikiwikiikiwiki3.14159265
ikiwikiikiwiki3.20091009
ikiwikiikiwiki3.20091017
ikiwikiikiwiki3.20091022
ikiwikiikiwiki3.20091023
ikiwikiikiwiki3.20091031
ikiwikiikiwiki3.20091113
ikiwikiikiwiki3.20091202
ikiwikiikiwiki3.20091218
ikiwikiikiwiki3.20100102.3
ikiwikiikiwiki3.20100122
ikiwikiikiwiki3.20100212
ikiwikiikiwiki3.20100302
ikiwikiikiwiki3.20100312
ikiwikiikiwiki3.20100403
ikiwikiikiwiki3.20100427
ikiwikiikiwiki3.20100501
ikiwikiikiwiki3.20100504
ikiwikiikiwiki3.20100515
ikiwikiikiwiki3.20100518
ikiwikiikiwiki3.20100518.2
ikiwikiikiwiki3.20100610
ikiwikiikiwiki3.20100623
ikiwikiikiwiki3.20100722
ikiwikiikiwiki3.20100804
ikiwikiikiwiki3.20100815
ikiwikiikiwiki3.20100831
ikiwikiikiwiki3.20100926
ikiwikiikiwiki3.20101019
ikiwikiikiwiki3.20101023
ikiwikiikiwiki3.20101112
ikiwikiikiwiki3.20101129
ikiwikiikiwiki3.20101201
ikiwikiikiwiki3.20101231
ikiwikiikiwiki3.20110105
ikiwikiikiwiki3.20110123
ikiwikiikiwiki3.20110124
ikiwikiikiwiki3.20110225

References

CWEs

CWE-79

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.