VDB

CVE-2026-5090

CVE-2026-5090 PUBLISHED

Template::Plugin::HTML versions through 3.102 for Perl allows HTML and JavaScript to be injected. The html_filter function did not escape single quotes. HTML attributes inside of single quotes could be have code injected. For example, the variable "var" in <a id='ref' title='[% var | html %]'> would not be properly escaped. An attacker could insert some limited HTML and JavaScript, for example, var = " ' onclick='while (true) { alert(1) }'" Note that arbitrary HTML and JavaScript would be difficult to inject, because angle brackets, ampersands and double-quotes would still be escaped.

EPSS 0.29% · 22.0th percentile

Risk Scores

EPSS Score
0.29%
22.0th percentile

Affected Products

VendorProductVersions
TODDRTemplate::Plugin::HTML0

Timeline

  • May 19, 2026 CVE Published
  • May 19, 2026 PoC Published
  • May 19, 2026 PoC Published
  • May 20, 2026 EPSS Score
  • May 20, 2026 Coalition ESS Score
  • May 20, 2026 Security Advisory
  • May 21, 2026 EPSS Score
  • May 22, 2026 EPSS Score
  • May 23, 2026 EPSS Score
  • May 24, 2026 EPSS Score
  • May 25, 2026 EPSS Score
  • May 26, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›