VDB
CVE-2026-5090
CVE-2026-5090
PUBLISHED
Template::Plugin::HTML versions through 3.102 for Perl allows HTML and JavaScript to be injected. The html_filter function did not escape single quotes. HTML attributes inside of single quotes could be have code injected. For example, the variable "var" in <a id='ref' title='[% var | html %]'> would not be properly escaped. An attacker could insert some limited HTML and JavaScript, for example, var = " ' onclick='while (true) { alert(1) }'" Note that arbitrary HTML and JavaScript would be difficult to inject, because angle brackets, ampersands and double-quotes would still be escaped.
EPSS 0.29% · 22.0th percentile
Risk Scores
EPSS Score
0.29%
22.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| TODDR | Template::Plugin::HTML | 0 |
Timeline
- May 19, 2026 CVE Published
- May 19, 2026 PoC Published
- May 19, 2026 PoC Published
- May 20, 2026 EPSS Score
- May 20, 2026 Coalition ESS Score
- May 20, 2026 Security Advisory
- May 21, 2026 EPSS Score
- May 22, 2026 EPSS Score
- May 23, 2026 EPSS Score
- May 24, 2026 EPSS Score
- May 25, 2026 EPSS Score
- May 26, 2026 EPSS Score