CVE-2015-3161: Beaker-Project Beaker
Medium severity, CVSS 4.8. EPSS: 0.8% chance of exploitation in the next 30 days.
The search bar code in bkr/server/widgets.py in Beaker before 20.1 does not escape </script> tags in string literals when producing JSON.
Affected products
- Beaker-Project Beaker: up to and including 20.0
Published 2017-09-06. Last modified 2026-06-17.