{"id":"PYSEC-2026-766","summary":"Zope XSS Vulnerability","details":"Cross-site scripting (XSS) vulnerability in Zope 2.8.x before 2.8.12, 2.9.x before 2.9.12, 2.10.x before 2.10.11, 2.11.x before 2.11.6, and 2.12.x before 2.12.3, 3.1.1 through 3.4.1. allows remote attackers to inject arbitrary web script or HTML via vectors related to the way error messages perform sanitization. NOTE: this issue exists because of an incomplete fix for CVE-2010-1104","aliases":["CVE-2011-4924","GHSA-vh6g-786f-hxxp","PYSEC-2026-3440"],"modified":"2026-07-13T16:43:17.362847440Z","published":"2026-07-02T14:13:17.937454Z","references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2011-4924"},{"type":"WEB","url":"https://github.com/zopefoundation/Zope/commit/37e4ea774acc668f6b430a45a6ab1e359710f590"},{"type":"WEB","url":"https://github.com/zopefoundation/Zope/commit/a0655194cb39ad88ce3323a3e489927c5f979c44"},{"type":"WEB","url":"https://access.redhat.com/security/cve/cve-2011-4924"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2011-4924"},{"type":"PACKAGE","url":"https://github.com/zopefoundation/Zope"},{"type":"WEB","url":"https://security-tracker.debian.org/tracker/CVE-2011-4924"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2012/01/19/16"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2012/01/19/17"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2012/01/19/18"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2012/01/19/19"},{"type":"PACKAGE","url":"https://pypi.org/project/zope2"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-vh6g-786f-hxxp"}],"affected":[{"package":{"name":"zope2","ecosystem":"PyPI","purl":"pkg:pypi/zope2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.12.22"},{"introduced":"2.13.0a1"},{"fixed":"2.13.12"}]}],"versions":["2.12.0","2.12.0.a1","2.12.0a2","2.12.0a3","2.12.0a4","2.12.0b1","2.12.0b2","2.12.0b3","2.12.0b4","2.12.0c1","2.12.1","2.12.10","2.12.11","2.12.12","2.12.13","2.12.14","2.12.15","2.12.16","2.12.17","2.12.18","2.12.19","2.12.2","2.12.20","2.12.21","2.12.3","2.12.4","2.12.5","2.12.6","2.12.7","2.12.8","2.12.9","2.13.0","2.13.0a1","2.13.0a2","2.13.0a3","2.13.0a4","2.13.0b1","2.13.0c1","2.13.1","2.13.10","2.13.11","2.13.2","2.13.3","2.13.4","2.13.5","2.13.6","2.13.7","2.13.8","2.13.9"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/zope2/PYSEC-2026-766.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}