VDB
GCVE-VVD-MAGEIA-2014-462
GCVE-VVD-MAGEIA-2014-462
Advisory Published
Cross-site scripting (XSS) vulnerability in util/templatetags/djblets_js.py
in Djblets before 0.7.30 for Django, as used in Review Board, allows remote
attackers to inject arbitrary web script or HTML via a JSON object, as
demonstrated by the name field when changing a user name (CVE-2014-3994).
Cross-site scripting (XSS) vulnerability in
gravatars/templatetags/gravatars.py in Djblets before 0.7.30 Django allows
remote attackers to inject arbitrary web script or HTML via a user display
name (CVE-2014-3995).
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | python-djblets | 0 (affected), 0.7.30-1.1.mga4 (unaffected) | — |
Aliases
Transitive aliases
PYSEC-2014-79PYSEC-2014-78GHSA-w7rq-8f2g-jvqrGSD-2014-5028EUVD-2014-4927GHSA-6mg9-jgmx-fc96CVE-2014-5028GHSA-4xf6-xr96-7vmpEUVD-2014-0016CVE-2014-5027EUVD-2014-4926EUVD-2014-0017GHSA-p869-r3h5-mpvvVVD-GENTOO-2014-522472GSD-2014-5027VVD-GENTOO-2014-512668GSD-2014-3995GSD-2014-3994VVD-GENTOO-2014-518304
Browse GCVE Records
74,355 records in the GCVE database · Updated July 23, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.