---
id: CVE-2007-0857
aliases:
  - GHSA-m84w-vgwf-p893
  - PYSEC-2026-678
title: MoinMoin Multiple cross-site scripting (XSS) vulnerabilities
summary: MoinMoin Multiple cross-site scripting (XSS) vulnerabilities
severity: medium
vendor: moin
product: moin
ecosystem: pip
affected:
  - moin < 1.5.7
patched:
  - moin 1.5.7
published: '2022-05-01'
updated: '2026-07-06'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-m84w-vgwf-p893'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2007-0857'
  - url: 'https://exchange.xforce.ibmcloud.com/vulnerabilities/32377'
  - url: 'http://moinmoin.wikiwikiweb.de/MoinMoinRelease1.5/CHANGES'
  - url: 'http://osvdb.org/31871'
  - url: 'http://osvdb.org/31872'
  - url: 'http://osvdb.org/31873'
  - url: 'http://secunia.com/advisories/24096'
  - url: 'http://secunia.com/advisories/24117'
  - url: 'http://www.osvdb.org/31874'
  - url: 'http://www.securityfocus.com/bid/22506'
  - url: 'http://www.ubuntu.com/usn/usn-421-1'
  - url: 'http://www.vupen.com/english/advisories/2007/0553'
tags:
  - osv
  - pip
epss: 0.0242
epssPercentile: 0.83316
ingestedAt: '2026-07-08T18:25:51.177Z'
---

## Overview

Multiple cross-site scripting (XSS) vulnerabilities in MoinMoin before 1.5.7 allow remote attackers to inject arbitrary web script or HTML via (1) the page info, or the page name in a (2) AttachFile, (3) RenamePage, or (4) LocalSiteMap action.

## Affected packages

- `moin < 1.5.7`

## Remediation

Upgrade to a patched release:

- `moin 1.5.7`
