CVE-2016-4807Medium· 4.8▾ TwilightPoC availableWeb2py Reflected XSS vulnerability
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 26.4 · likelihood 0.6 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
2.3%
2.3% → 2.9%
Exploit-DB (last check)
Web2py versions 2.14.5 and below was affected by Reflected XSS vulnerability, which allows an attacker to perform an XSS attack on logged in user (admin).
web2py <= 2.14.5Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2016-4808Medium· 4.5Web2py Cross-Site Request Forgery vulnerability
CVE-2026-25198Medium· 4.7web2py has an Open Redirect Vulnerability
CVE-2016-3954Medium· 5.5web2py exposure of sensitive information
CVE-2022-33146Medium· 6.1Open redirect in web2py
CVE-2023-22432Medium· 6.1Open redirect in web2py