CVE-2016-0011: Microsoft SharePoint Foundation
Medium severity, CVSS 5.4. EPSS: 5.3% chance of exploitation in the next 30 days.
Microsoft SharePoint Server 2013 SP1 and SharePoint Foundation 2013 SP1 allow remote authenticated users to bypass intended Access Control Policy restrictions and conduct cross-site scripting (XSS) attacks by modifying a webpart, aka "Microsoft SharePoint Security Feature Bypass," a different vulnerability than CVE-2015-6117.
Affected products
Published 2016-01-13. Last modified 2026-06-17.