CVE-2013-2311: WEB2PY
Medium severity, CVSS 4.3. EPSS: 1.2% chance of exploitation in the next 30 days.
Cross-site scripting (XSS) vulnerability in static/js/share.js (aka the social bookmarking widget) in Web2py before 2.3.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected products
- WEB2PY WEB2PY: up to and including 2.2.1; version 1.16.0 only; version 1.17.0 only; version 1.18.0 only; version 1.19.0 only; version 1.20.0 only; …
Published 2013-05-22. Last modified 2026-06-16.