{"id":"CVE-2021-3994","aliases":["GHSA-2v5j-q74q-r53f","PYSEC-2021-438"],"url":"https://o3.security/vulnerability/CVE-2021-3994","summary":"django-helpdesk is vulnerable to Cross-site Scripting","details":"django-helpdesk is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","published":"2021-12-01T11:15:08.153Z","modified":"2026-07-09T00:36:40.473132Z","cvss":{"score":9.6,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"},"epss":{"score":0.01354,"percentile":0.69047,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"PyPI","name":"django-helpdesk","fixedVersion":"0.3.2"}],"fix":{"url":"https://github.com/django-helpdesk/django-helpdesk/commit/a22eb0673fe0b7784f99c6b5fd343b64a6700f06","label":"django-helpdesk/django-helpdesk@a22eb06"},"references":[{"type":"FIX","url":"https://github.com/django-helpdesk/django-helpdesk/commit/a22eb0673fe0b7784f99c6b5fd343b64a6700f06"},{"type":"FIX","url":"https://huntr.dev/bounties/be7f211d-4bfd-44fd-91e8-682329906fbd"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-09T00:36:40.473132Z"}}