CVE-2016-20098: Toolbox-Team Reddit-Moderator-Toolbox
Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.
Moderator Toolbox (reddit-moderator-toolbox) before 4.0.14 contains a stored cross-site scripting vulnerability in the removalreasons module, which inserts subreddit toolbox wiki fields into popup HTML without encoding. Attackers who can edit the toolbox wiki page can plant JavaScript in fields like pmsubject, header, or reason titles to act with moderators' Reddit sessions.
Affected products
- Toolbox-Team Reddit-Moderator-Toolbox: before 4.0.14 (fixed in 4.0.14)
Published 2026-10-09. Last modified 2026-10-09.