CVE-2016-7146: Moinmo Moinmoin

Medium severity, CVSS 6.1. EPSS: 1.2% chance of exploitation in the next 30 days.

MoinMoin 1.9.8 allows remote attackers to conduct "JavaScript injection" attacks by using the "page creation or crafted URL" approach, related to a "Cross Site Scripting (XSS)" issue affecting the action=fckdialog&dialog=attachment (via page name) component.

Affected products

  • Moinmo Moinmoin: version 1.9.8 only

Published 2016-11-10. Last modified 2026-06-17.