Medium severity5.4NVD Advisory· Published Oct 9, 2026· Updated Oct 9, 2026
CVE-2016-20098
CVE-2016-20098
Description
Moderator Toolbox (reddit-moderator-toolbox) before 4.0.14 contains a stored cross-site scripting vulnerability in the removalreasons module, which inserts subreddit toolbox wiki fields into popup HTML without encoding. Attackers who can edit the toolbox wiki page can plant JavaScript in fields like pmsubject, header, or reason titles to act with moderators' Reddit sessions.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2(expand)+ 1 more
- (no CPE)
- (no CPE)range: <4.0.14
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.