← Vulnerability feed

Vulnerability record · CVE-2011-1891 · published 15 September 2011

CVE-2011-1891: Microsoft sharepoint foundation cross-site scripting vulnerability

Microsoft · Sharepoint Foundation

Cross-site scripting (XSS) vulnerability in Microsoft Windows SharePoint Services 3.0 SP2, and SharePoint Foundation 2010 Gold and SP1, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters in a request to a script, aka "Contact Details Reflected XSS Vulnerability."

4.3 CVSS 2.0 Medium EPSS 17% · top 3.1% CWE-79 · Cross-site scripting
4.3CVSS 2.0 base score
17%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
6References
16 Jun 2026Last modified by NVD

Description

Cross-site scripting (XSS) vulnerability in Microsoft Windows SharePoint Services 3.0 SP2, and SharePoint Foundation 2010 Gold and SP1, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters in a request to a script, aka "Contact Details Reflected XSS Vulnerability."

AV:N/AC:M/Au:N/C:N/I:P/A:N

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2011-1891 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-0604Microsoft SharePoint application package markup validation RCEMicrosoft SharePoint fails to validate the source markup of an application package, allowing crafted packages to execute code on the server. This is …KEVEPSS 100%analysed10.0CVE-2013-1330Microsoft sharepoint foundation improper input validation vulnerabilityThe default configuration of Microsoft SharePoint Portal Server 2003 SP3, SharePoint Server 2007 SP3 and 2010 SP1 and SP2, and Office Web Apps 2010 d…EPSS 27%9.9CVE-2020-1595Microsoft sharepoint enterprise server download of code without integrity check vulnerability<p>A remote code execution vulnerability exists in Microsoft SharePoint where APIs aren't properly protected from unsafe data input. An attacker who …EPSS 2.0%9.9CVE-2020-1210Microsoft sharepoint enterprise server download of code without integrity check vulnerability<p>A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package.…EPSS 1.9%9.8CVE-2023-21716Microsoft Word integer overflow remote code executionCVE-2023-21716 is a critical remote code execution flaw in Microsoft Word, tied to an integer overflow (CWE-190). The record gives only a one-line de…EPSS 85%analysed9.8CVE-2020-1025Microsoft lync improper input validation vulnerabilityAn elevation of privilege vulnerability exists when Microsoft SharePoint Server and Skype for Business Server improperly handle OAuth token validatio…EPSS 5.9%9.3CVE-2015-1682Microsoft excel memory buffer overflow vulnerabilityMicrosoft Office 2010 SP2, Excel 2010 SP2, PowerPoint 2010 SP2, Word 2010 SP2, Office 2013 SP1, Excel 2013 SP1, PowerPoint 2013 SP1, Word 2013 SP1, O…EPSS 19%9.3CVE-2015-0085Microsoft excel vulnerabilityUse-after-free vulnerability in Microsoft Office 2007 SP3, Excel 2007 SP3, PowerPoint 2007 SP3, Word 2007 SP3, Office 2010 SP2, Excel 2010 SP2, Power…EPSS 19%

Source: NIST National Vulnerability Database (record CVE-2011-1891), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.