VYPR
Low severityNVD Advisory· Published Mar 29, 2011· Updated Jun 16, 2026

CVE-2011-0728

CVE-2011-0728

Description

Cross-site scripting (XSS) vulnerability in templatefunctions.py in Loggerhead before 1.18.1 allows remote authenticated users to inject arbitrary web script or HTML via a filename, which is not properly handled in a revision view.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
loggerheadPyPI
< 1.18.11.18.1

Affected products

6
  • cpe:2.3:a:michael_hudson-doyle:loggerhead:*:*:*:*:*:*:*:*+ 4 more
    • cpe:2.3:a:michael_hudson-doyle:loggerhead:*:*:*:*:*:*:*:*range: <=1.18
    • cpe:2.3:a:michael_hudson-doyle:loggerhead:1.10:*:*:*:*:*:*:*
    • cpe:2.3:a:michael_hudson-doyle:loggerhead:1.17:*:*:*:*:*:*:*
    • cpe:2.3:a:michael_hudson-doyle:loggerhead:1.6:*:*:*:*:*:*:*
    • cpe:2.3:a:michael_hudson-doyle:loggerhead:1.6.1:*:*:*:*:*:*:*
  • ghsa-coords
    Range: < 1.18.1

Patches

Vulnerability mechanics

References

15

News mentions

0

No linked articles in our index yet.