← Vulnerability feed

Vulnerability record · CVE-2011-5025 · published 29 December 2011

CVE-2011-5025: Yaws cross-site scripting vulnerability

Yaws · Yaws

Multiple cross-site scripting (XSS) vulnerabilities in the wiki application in Yaws 1.88 allow remote attackers to inject arbitrary web script or HTML via (1) the tag parameter to editTag.yaws, (2) the index parameter to showOldPage.yaws, (3) the node parameter to allRefsToMe.yaws, or (4) the text parameter to editPage.yaws.

4.3 CVSS 2.0 Medium EPSS 2.7% · top 14.8% CWE-79 · Cross-site scripting
4.3CVSS 2.0 base score
2.7%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
16 Jun 2026Last modified by NVD

Description

Multiple cross-site scripting (XSS) vulnerabilities in the wiki application in Yaws 1.88 allow remote attackers to inject arbitrary web script or HTML via (1) the tag parameter to editTag.yaws, (2) the index parameter to showOldPage.yaws, (3) the node parameter to allRefsToMe.yaws, or (4) the text parameter to editPage.yaws.

AV:N/AC:M/Au:N/C:N/I:P/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2011-5025 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-24379Yaws xml external entity (xxe) vulnerabilityWebDAV implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to XXE injection.EPSS 3.4%9.8CVE-2020-24916Yaws os command injection vulnerabilityCGI implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to OS command injection.EPSS 17%7.5CVE-2017-10974Yaws web server path traversal allows unauthenticated file disclosureYaws 1.91 fails to properly block HTTP directory traversal when a request path begins with the /%5C sequence, letting an attacker read files outside …EPSS 81%analysed6.5CVE-2011-4350Yaws path traversal vulnerabilityYaws 1.91 has a directory traversal vulnerability in the way certain URLs are processed. A remote authenticated user could use this flaw to obtain co…EPSS 16%6.1CVE-2016-1000108Yaws open redirect vulnerabilityyaws before 2.0.4 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the pr…EPSS 1.1%5.5CVE-2020-12872Yaws inadequate encryption strength vulnerabilityyaws_config.erl in Yaws through 2.0.2 and/or 2.0.7 loads obsolete TLS ciphers, as demonstrated by ones that allow Sweet32 attacks, if running on an E…EPSS 0.39%5.0CVE-2010-4181Yaws path traversal vulnerabilityDirectory traversal vulnerability in Yaws 1.89 allows remote attackers to read arbitrary files via ..\ (dot dot backslash) and other sequences.EPSS 8.5%5.0CVE-2009-4495Yaws improper input validation vulnerabilityYaws 1.85 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or po…EPSS 9.0%

Source: NIST National Vulnerability Database (record CVE-2011-5025), CISA KEV, FIRST EPSS (scores of 2026-10-03). This page is refreshed as NVD updates the record.