CVE-2016-4807: WEB2PY
Medium severity, CVSS 4.8. EPSS: 2.3% chance of exploitation in the next 30 days.
Web2py versions 2.14.5 and below was affected by Reflected XSS vulnerability, which allows an attacker to perform an XSS attack on logged in user (admin).
Affected products
- WEB2PY WEB2PY: up to and including 2.14.5
Published 2017-01-11. Last modified 2026-06-17.