{"id":"CVE-2021-25986","details":"In Django-wiki, versions 0.0.20 to 0.7.8 are vulnerable to Stored Cross-Site Scripting (XSS) in Notifications Section. An attacker who has access to edit pages can inject JavaScript payload in the title field. When a victim gets a notification regarding the changes made in the application, the payload in the notification panel renders and loads external JavaScript.","aliases":["GHSA-3m3h-v9hv-9j4h","PYSEC-2021-850"],"modified":"2026-02-21T01:10:27.322902Z","published":"2021-11-23T20:15:10.583Z","references":[{"type":"ADVISORY","url":"https://github.com/django-wiki/django-wiki/commit/9eaccc7519e4206a4d2f22640882f0737b2da9c5"},{"type":"ADVISORY","url":"https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25986"},{"type":"FIX","url":"https://github.com/django-wiki/django-wiki/commit/9eaccc7519e4206a4d2f22640882f0737b2da9c5"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/django-wiki/django-wiki","events":[{"introduced":"0"},{"fixed":"9eaccc7519e4206a4d2f22640882f0737b2da9c5"}]}],"versions":["alpha/0.0.12","alpha/0.0.13","alpha/0.0.14","alpha/0.0.15","alpha/0.0.16","alpha/0.0.17","alpha/0.0.18","alpha/0.0.19","alpha/0.0.20","alpha/0.0.22","alpha/0.0.23","alpha/0.0.24","alpha/0.4a1","alpha/0.4a2","alpha/0.4a3","alpha/0.4a4","alpha/0.4a5","beta/0.3b1","beta/0.3b2","beta/0.3b3","beta/0.3b4","beta/0.4b1","beta/0.4b2","beta/0.4b3","beta/0.6b1","beta/0.6b2","releases/0.1","releases/0.1.1","releases/0.1.2","releases/0.2","releases/0.2.1","releases/0.2.2","releases/0.2.3","releases/0.2.4","releases/0.2.5","releases/0.2b1","releases/0.2b2","releases/0.3","releases/0.3.1","releases/0.4","releases/0.4.1","releases/0.4.2","releases/0.4.3","releases/0.4.4","releases/0.4.5","releases/0.5","releases/0.6","releases/0.7","releases/0.7.1","releases/0.7.2","releases/0.7.3","releases/0.7.4","releases/0.7.5","releases/0.7.6","releases/0.7.7","releases/0.7.8"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-25986.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"}]}