---
id: CVE-2016-20098
title: >-
  Moderator Toolbox (reddit-moderator-toolbox) before 4.0.14 contains a stored
  cross-site scripting vulnerability in the removalreasons module, which inserts
  subreddit toolbox wiki fields into popup HTML without encoding
summary: >-
  Moderator Toolbox (reddit-moderator-toolbox) before 4.0.14 contains a stored
  cross-site scripting vulnerability in the removalreasons module, which inserts
  subreddit toolbox wiki fields into popup HTML without encoding. Attackers who
  can…
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
published: '2026-10-09'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T20:17:08.603'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2016-20098'
references:
  - url: 'https://github.com/toolbox-team/reddit-moderator-toolbox'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/toolbox-team/reddit-moderator-toolbox/commit/26f45ba21d84cecb92b1a820896ad3bf5254376e
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/moderator-toolbox-before-4.0.14-stored-xss-via-removal-reasons-configuration
    label: disclosure@vulncheck.com
tags:
  - nvd
ingestedAt: '2026-10-09T18:07:39.415Z'
---

## Overview

Moderator Toolbox (reddit-moderator-toolbox) before 4.0.14 contains a stored cross-site scripting vulnerability in the removalreasons module, which inserts subreddit toolbox wiki fields into popup HTML without encoding. Attackers who can edit the toolbox wiki page can plant JavaScript in fields like pmsubject, header, or reason titles to act with moderators' Reddit sessions.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
