{"id":"CVE-2016-4807","aliases":["GHSA-pvcp-73cg-6f77","PYSEC-2026-1063"],"url":"https://o3.security/vulnerability/CVE-2016-4807","summary":"Web2py Reflected XSS vulnerability","details":"Web2py versions 2.14.5 and below was affected by Reflected XSS vulnerability, which allows an attacker to perform an XSS attack on logged in user (admin).","published":"2017-01-11T16:59:00.237Z","modified":"2026-08-07T14:31:48.710204Z","cvss":{"score":4.8,"severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":3,"affectedPackages":[{"ecosystem":"PyPI","name":"web2py","fixedVersion":null}],"fix":null,"references":[{"type":"EVIDENCE","url":"http://packetstormsecurity.com/files/137070/Web2py-2.14.5-CSRF-XSS-Local-File-Inclusion.html"},{"type":"EVIDENCE","url":"https://www.exploit-db.com/exploits/39821/"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2016-4807"},{"type":"PACKAGE","url":"https://github.com/web2py/web2py"},{"type":"WEB","url":"https://www.exploit-db.com/exploits/39821"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T14:31:48.710204Z"}}