CVE-2013-2311: WEB2PY

Medium severity, CVSS 4.3. EPSS: 1.2% chance of exploitation in the next 30 days.

Cross-site scripting (XSS) vulnerability in static/js/share.js (aka the social bookmarking widget) in Web2py before 2.3.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Affected products

  • WEB2PY WEB2PY: up to and including 2.2.1; version 1.16.0 only; version 1.17.0 only; version 1.18.0 only; version 1.19.0 only; version 1.20.0 only; …

Published 2013-05-22. Last modified 2026-06-16.